January 2017 Journal
WORDS is a monthly journal of Bitcoin commentary. This issue collects the January 2017 writing in the WORDS archive. For the uninitiated, getting up to speed on Bitcoin can seem daunting. Content is scattered across the internet, in some cases behind paywalls, and content has been lost forever. Thatâs why we made this journal, to preserve and further the understanding of Bitcoin.
Crashes and Hyperinflation
By Daniel Krawisz
Posted January 8, 2017
Introduction
John Maynard Keynes famously said that âthe market can stay irrational longer than you can stay solvent.â But the converse is also true: the market can become rational suddenly, and sooner than you expect. When people come to expect irrationality as a matter of course, then they are vulnerable to a sudden onset of rationality. Crashes and hyperinflationary events can be treated as events caused by a society that has gradually become complacent in its irrationality. A crash happens when people become too committed to particular enterprises and there is no one left to help out with a mistake. Hyperinflations happen when people begin to accept lower levels of inflation as a matter of course.
Understanding these phenomena is a matter of understanding when people prefer to hold cash or buy investments, the effect that this decision has on the economy, and how inflation of the money supply changes the incentives of the decision. That is what this article is about, and here are my definitions of the concepts Iâll be discussing.
Money: Money is an abstract concept that applies to whatever good is the most liquid. The value of having money, from the standpoint of an investor, is that it is the easiest good to get rid of in the market, which is what it means to be the most liquid. This means that if there is something especially good for sale, the person with ready cash on hands gets first dibs on it.
Cash: Different goods can be money at different times. Because I want to talk about the process by which a good loses its status as money, I will use cash to refer to a good that is money now, but in the future might no longer be money. If that happens, the status of money would switch to some other good, and cash would become worthless paper or worthless numbers in a computer. Whereas money is an abstract concept, cash is a specific good.
Savings: the portion of an investorâs portfolio held in cash.
Investment: goods other than cash which are bought because of an expected future benefit rather than for immediate consumption. This could be because it provides income, like a bond or a stock with a dividend, or because you expect its price to go up eventually. I donât distinguish between different kinds of investments because the difference is not relevant to the issues I am discussing. If I use a company stock as an example, I could just as easily be talking about a bond, or commodity future, or a baseball card, or anything. When I say âstock market,â Iâm talking about the market for all investments, not a literal stock market.
This article is entirely about cash versus any other investment and why someone would prefer one over the other, so that is why cash is not considered an investment for the purposes of this article. However, cash can be an investment in the sense that someone might buy it because he anticipates it becoming more expensive later. If he expect a stock market crash, he can go into cash with the expectation that youâll be able to buy stocks again more cheaply once the crash happens. One can also hold cash without investing because cash has a present benefit, which is its liquidity. This is discussed in more detail below.
Inflation: Inflation here refers to an increase in the money supply rather than an increase of prices. The reason is that if an investor knows the money supply is increasing, then he will anticipate his cash growing less valuable relative to what it would have been if the supply had not grown. He will do this even if there is no apparent price inflation yet. In general, investors learn to react to causes in anticipation of price changes because if they wait around for price changes to actually happen, then they have missed an opportunity.
This article presents an idealized picture of the economy in which it is objective what is money and what isnât, and in which the money is managed by the issuer in a very simple way, that is, by issuing more. Our economy is a lot more complicated, but I would contend (without defending here) that the way to understand the real world is to unravel the mess and find this idealized scenario within. I donât think that the real-world national currencies work in a fundamentally different way from what I have described.
I recently wrote an article on the growth of money called âItâs Not About the Technology, Itâs About the Moneyâ. This article can be seen as a continuation of that one, but it can be read independently. That article is mostly about a positive-feedback between the use of money and its value. That is, as more people use a good as money, it becomes more useful as money, as a result of becoming more liquid. This article is about how money interacts with the rest of the economy after it has matured and about how mismanagement by an issuer can cause it to fail.
The Value of Money
One thing that confused people a lot about Bitcoin in the very early days was how could it possibly be valuable, given that itâs nothing but a bunch of numbers in computers. Itâs not that people were foolish to think that Bitcoin wasnât valuable back then; actually they were foolish for not asking the same question about all forms of money. For already at that time people were paying real dollars for numbers in a computer (World of Warcraft gold or Farmville upgrades), and most real dollars were by that time also nothing more than numbers in a computer. Thus, there was nothing special about Bitcoin as a form of money.
What prevents us all from just throwing our dollar bills on the ground and saying, âThese were all just pieces of paper all along! Why did I ever think they were valuable?â Seemingly not a likely scenario, but no currency lasts forever. I will argue that money serves a valuable function in investment, and the benefits which accrue to those who invest successfully in money explains why people are willing to hold on to it.
First I wish briefly to dispel the notion that moneyâs value derives from its use as a medium-of-exchange. Money is useful as a medium-of-exchange because it is valuable, not the other way around. This can be seen to be true by the fact that you can use money as a medium-of-exchange without adding to its demand. If you earn a bunch of money and then spend it again almost immediately after, youâve used the money as a medium-of-exchange but you got rid of it so quickly that you have immediately negated the effect of demanding it.
In order for the value of money to go up, people have to want to hold more of it at a time or hold it for longer periods of time. In other words, the value of money is caused by its demand for use as savings instead. Someone can live hand-to-mouth and have only an amount of money they need on hand for the immediate future. Other people can have a large savings but still spend roughly same amount that they earn. Other people can spend less or more than what they earn in order to increase or decrease their savings. The value of money can be understood in terms of the reasons that make people want a lot of savings or a little, and changes to the value of money, both slow and rapid, can be explained in terms of reasons that change how much people value their savings.
A Function of Savings
Here is a very real benefit of holding cash. People with cash are able to remain agnostic as to what they want to buy until the very last moment. They are more prepared for unexpected expenses and opportunities, and therefore free from the need to plan. A person with savings can treat as ordinary expenses things that would be disasters for people who didnât have savings. Most people, if they have a big enough income, would choose to buy insurance for their car, home, or health. But someone with a lot of savings doesnât need as much help from other people.
He is also more in a position to help other people who have been struck with disaster. Not only is he in a position to be nice if people should need help, but he is also in a position to profit from doing so. A business has certain expenses that it must make regularly or go out of business. It must make payroll, for example. There is always some risk that the company will not have enough revenue for some time. The company could reduce this risk by holding extra cash, or it could use the cash to buy more capital and attempt to expand its future production. It is difficult to maintain the right balance because circumstances are constantly changing and uncertain, so even fundamentally sound businesses sometimes end up in an immediate need for cash. When that happens the businessâs stock price goes down because their risk of insolvency goes up. They may also be willing to take out a loan at a very favorable rate for the lender. An investor with cash on hand can help an otherwise worthwhile business survive by taking care of their immediate expenses and in return can buy the stock at a good value or earn a good rate of interest off a bond.
However, this kind of opportunity does not last forever. Investors who have cash get first dibs on it. When one is in cash, one is uncommitted and ready for opportunity. By contrast, a lot of the potential value of an investment depends on being able to choose when to sell it. A given investment can always go down for a while, even if the investor ultimately is able to sell it at a profit. An investment has a much better chance of being valuable if the investor can expect to hold it long enough that a good selling opportunity will have occurred. Furthermore, although on ordinary days it may seem as if a stock will be easy to sell at any time, there are days when most investments other than cash drop at the same time. During these days it may not be possible to sell investments fast enough and it is much better to have cash on hand in the first place.
Thus, a cash-holder benefits himself by being prepared to take advantage of the best deals, and provides the corresponding benefit to the economy of being prepared to jump in where help is needed. The cash-holders benefit the economy by deciding which troubled businesses can be redeemed and then providing the necessary cash.
Of course, it is not the cash itself that fixes the troubled business. The cash is used to buy the necessary resources to do so. For example, it could be used to pay employees to keep them working until some new revenue comes in. Thus, the existence of cash-holders in an economy can be thought of as meaning that some fraction of the economyâs production is reserved to be diverted to error correction.
The Problem of Overinvestment
A cash-holder can live idly and can avoid making investments. It would be a mistake to look at this person and say that he is not contributing anything. The ability to live idly is also an ability to become committed at any time, to whatever has the greatest need. People depend on this service because it is impossible to avoid error, and insofar as everyone in the economy depends on everyone else, we are all subject to one anotherâsâ errors.
A person who is uncommitted cannot step in to fix every problem that might arise. Eventually he will be committed himself and can take on no additional projects. Therefore, if there is a lot of money held in cash, then there is a lot of tolerance for error in the economy, whereas if there is little, then the economy is much less error-tolerant. Thus, the problem of overinvestment is a reduced capacity for error-correction. If everyone decides to put their money to work now, then theoretically more can be accomplished at once, but at a much greater risk of failure. If a lot of cash-holders remain on the sidelines, then less can be ventured, but at a greater probability of success.
Because an error in one business can affect the businesses that depend on it, then when people are overinvested, not only is there a greater risk of error, but the consequences of errors are more severe. For example, suppose that two businesses, A and B, both make short-term errors that require correction. In a healthy economy, maybe one or the other would have failed, but the other would have been rescued, whereas in an overinvested economy, both fail. Now suppose that business C can tolerate either A or B failing to follow through on a deal, but not both. Then C also needs to be rescued. However, it too evidently fails as well.
Thus, it is possible, in an overinvested economy, for a small error to turn into a big error because there is no one prepared to fix it while it is small. This is an economic crash. When too many people become invested and not enough remain uncommitted, then everyone in the economy must move in lock-step with one another. In a healthy economy, there is a lot more room for everybody screw up.
Why Money Persists
I am now in a position to talk about why money persists, despite the fact that it is merely a shared hallucination. Why donât people, so to speak, wake up and throw their money on the ground? In my previous article I explained the growth of money as a step-by-step process in which a good becomes monetized as one investor after another comes to treat it like money.
One might also suppose that the opposite process is possible, in which investors lose confidence in their money as they successively dump it, one by one. In order to explain the persistence of money, we would need a reason for someone to want to buy cash that another person wanted to dump.
Let us suppose that an investor was actually worried about his cash losing all value. This person would prefer to hold investments over cash under circumstances in which someone else would prefer to hold cash. Or, conversely, let us suppose that he loves stocks so much and doesnât understand the value of cash very well that he sells everything so as to be fully invested. Either way, the effect is the same. When he sells cash for investments, he very slightly increases the price of the stock market relative to the supply of cash. He has therefore very slightly increased the demonetization risk of cash and simultaneously the risk of a crash in the stock market.
The other investors may respond to his move by judging the demonetization risk or the stock market crash risk to be greater. If they judge the crash risk to be greater, then they will sell off stocks for additional cash, thus opposing the first investorâs action. If they judge the demonetization risk to be greater, then they will follow him and dump their cash themselves.
An old and consequently well-established currency will tend to be perceived as secure because the investors have a lot of experience seeing one another rely on cash as a safe haven. Thus, they will tend to (correctly) perceive the stock market as more risky than cash. On the other hand, if there is reason to believe that other investors are losing confidence in their money, then it is possible for other investors to prefer the stock market risk to the currency risk. If enough of them do this, then the currency is demonetized, just as they had feared.
The persistence of money, therefore, is explained by the fact that there is a more immediate need to reduce risk from investments rather than from demonetization. There is even a natural price for money. It is not like an ordinary price, which is the ratio by which two goods are exchanged. But you can think of the price of money as being the ratio of the total supply of money to some measure of the value of all investments in the economy. (In the real world, there are many different numbers that one could use to represent this price because people can disagree about how to correctly measure each of these.)
Changes to the Supply of Money
This section is about how changes to the money supply change investorsâ incentives about whether to hold cash or to be invested. Deflation is when the supply decreases, and inflation is when it increases. The most important thing about changes to the money supply is that they happen at specific places as a result of specific actions. Whenever there is deflation, there is a deflator. Whenever there is inflation, there is an inflator. In other words, money doesnât generate or disappear evenlyâsome specific person holds it.
Deflation is true charity because the deflator works or invests to earn money and then destroys it rather than demanding anything back. Therefore, people donât do it very much. Inflation is the one you need to worry about because the person who does it gets money for nothing. That means everyone would do it if they could get away with it. Someone who can just print up money has a big advantage over someone who actually saves money because he can print up more whenever he wants. He can take advantage of good deals immediately rather than putting in the work of collecting a sum of cash in the first place. Therefore, someone who can print money discourages everyone else from holding cash. They are incentivized to invest instead.
Of course, the inflator does not actually do anything to cause more resources to come into existence to match the new money he creates. He drives people away from their saving and into investments. Prices rise because they are all buying. There is no one left to who is prepared to correct errors. The investors cannot because they have reduced their savings. The inflator cannot because prices have risen and production cannot be diverted as easily as before. Thus, although the inflator appears, to the rest of the economy, like an investor with a lot of cash on hand, the economy is not safe. It is overinvested.
Failure to Remain a Safe Haven
A crash occurs when an unstable market sustains an error that spreads throughout like a row of dominos and investors flee back into cash. In order for a demonetization event to occur, the currency risk must remain greater than the stock market risk, even as more and more investors pile into stocks. The scenario I described above is possible, but it is kind of weird because it describes a demonetization event with no cause other than one lone investor with very infectious paranoia.
However, with the right inflation schedule, an inflator can cause this to happen. The greater the rate of inflation, the more will investors prefer the risk of investment to the safety of cash. The economy can still function without an established form of money, or with an alternative money, so there is always some rate of inflation that is too high to be sustainable. All that must happen is for the inflator to be driven to bring the rate of inflation up to the level that it becomes preferable to stop holding cash.
As the inflation rate increases, and as investors more and more prefer to take on risk, the error-correcting function of cash-holding is reduced without, at first, being replaced by anything. Instead, the economy must change so that errors are less likely in the first place. Enterprises must become more self-sufficient, and less reliant on long-term profits. In other words, the economy becomes more primitive.
If the economy compensates more quickly than the inflator can spend his new money, then he can find that he must inflate at faster and faster rates in order to sustain the same level of consumption. If he is unwilling to reduce his level of consumption, then he can reach an unsustainable rate of inflation. That is when people start to think of their cash as paper or meaningless numbers rather than stores of value.
Conclusion
I think of this article as being the last of a trilogy, the first two being âReciprocal Altruism in The Theory of Moneyâ, and âItâs Not About The Technology, itâs About the Moneyâ. The first article is an attempt to explain the use of money as a game. The second is about the growth of money, and this last one is about the death of money.
Because just about any good can be used as money, it is better to think of money as a behavior rather than as a thing. The money good is often something that is not very useful; it is something that is easy to count and difficult to reproduce. Money is rarely demanded to be consumed. Even something gold, which has important uses in industry or as jewelry, is more often just stored away. It is not, therefore, the nature of the specific good that is used which makes money useful. It is the way people treat it.
The way that people treat money is as a thing which is good for being liquid, or in other words, a thing that is always demanded everywhere. This is not an intrinsic property of any good. It is a property that is established by tradition. Every time people accept money, they are reinforcing that tradition. They are also making an investment in it, because there is no guarantee that the tradition will be as strong by the time they get around to spending the money. But as long as people continually make that investment, the tradition continues.
Despite the fact that people who acquire money do not necessarily have benevolent feelings about doing so, it makes sense to look at money as a form of altruism known to biologists as reciprocal altruism. In reciprocal altruism, one animal does something at its own expense which is immediately beneficial to another. The animal can afford to do this because it lives in a community of altruists, so it will eventually benefit from another animalâs altruism.
A necessary condition for reciprocal altruism to persist in a population is for non-altruists to be identified and excluded. Otherwise a group of moochers can live off the altruists and grow until altruism is unsustainable. This is accomplished in a money economy by the fact that people canât have a negative balance. People must be altruists first (earn) and beneficiaries second (spend).
Altruism may at first appear to be a strange way to look at money because it is understood that people acquire money for selfish reasons. However, in biology, there is no such thing as true altruism, or at least if there were, they would soon be exploited to death. There is only apparent altruism. The theory of reciprocal altruism tells us that it is possible for an animal to appear to be altruistic in the short term, but later to receive help from others when it cannot help itself. If an alien came down to Earth, and observed a miser he might well see the miserâs behavior as altruistic because the miser appears to work hard at othersâ bidding without receiving anything useful in return. Only after the alien observes that everyone else also attempts to acquire money would he understand the miserâs selfishness.
Because money being a social behavior, so its value depends on the society using it rather than the physical nature of the good being used. Because there can be more or fewer people using a kind of money and because they can demand more or less money, a kind of money can be more or less useful depending on the society in which a person finds himself. In other words, a person can find himself in a more or less altruistic society, and as a result, his money can be more or less valuable.
The network effect explains the initial growth of money out of a good which may have very little value initially. Because an initial investor in money will be rewarded much more than a late investor, initial investors have some incentive to take on additional risk and grab some when it is worthless. In doing so, they make it more immediately useful because they provide some initial demand that others can rely on. As money grows, there is a line of investors, begining with the most prescient, which leads money from its initial state to its central position in the economy.
The death of money follows the same process, in which the most prescient investors flee first, followed by more and more people until it no longer has value as money. This could theoretically happen on its own but one would expect it to be instigated by a superior competitor coming on the market or by an inflationary monetary policy which makes it a lot less useful.
The network effect explains why money grows and shrinks, but it does not explain why money would reach an equilibrium. It also does not explain why people hold more cash than they need immediately. The reason is that cash serves an investment function, so investors need to hold large amounts of it. The equilibrium value of money is the point where investors no longer prefer to hold more cash, and instead prefer to hold more stocks or bonds or other investments instead.
That is what I think of money. Now, for the good of society, earn as many bitcoins as you can!

Further Reading
- Money, Bank Credit, and Economic Cycles by JesĂșs Huerta de Soto
- Man, Economy, and State by Murray Rothbard
- The Austrian Theory of the Trade Cycle
- The Theory of Money and Credit by Ludwig von Mises
A Brief History of Bitcoin
By Junseth
Posted January 25, 2017
The End of the Bitcoin Natural Ponzi
When the World Bank released its whitepaper on Bitcoin back in July 2014, I was astounded by their stupid. Two years later, Iâm humbled by their reasonableness. The abstract of the paper begins with what I think is a very reasonable definition of what a Ponzi scheme is:
Ponzis are among the most ubiquitous and least understood phenomena of economic life. They acquired a certain salience with the global financial crisis of 2008 and the crash of Bernie Madoffâs celebrated Ponzi scheme. This paper explains the structure of Ponzi schemes and argues that what makes this such a troubling phenomenon is its ability to be camouflaged amid legitimate practices. It is shown, for instance, that the common practice of giving stock options to employees could be a potential Ponzi that allows corporations to flourish for a while by borrowing from its own future. The paper discusses the need for intelligent regulation to incise harmful Ponzis (not all Ponzis are harmful) while taking care not to damage the legitimate activities that surround them.
The rest of the paper takes a look at the structure of a Ponzi, and defines them as both fraudulent Ponzis, purposely created to bilk investors, and naturally occurring Ponzi schemes that are caused by raw speculation. The paper is not sophisticated in aspect, but I think it is accidentally prescient. Since itâs release, I think that I have come around to the idea that naturally occurring Ponzis are all over the place. Gold might be one such item. It has very few uses, but is value dense, though itâs notable that its value is almost entirely due to speculation. It works well as money because of its scarcity and its nearly utter uselessness for use anywhere else. That said, it relies largely on speculative inflows.
Bitcoin has been, to date, very similar. Itâs slow release schedule (mining) ensures scarcity though math + economics. But, honestly, until recently, its value has almost been completely based on inflows of money. Thanks to Libertarians, much of the value was buttressed by an ideological desire to see government crumble at the site of an alternative to fiat. Since those days, I think that the honest among us have come to understand that without government, there is no use for Bitcoin. Because, while the Libertarians provided what amounted to ideology-based price support, as Bitcoin has matured, we have begun to see its use among those who have no alternatives.
The Beginning of a Circular Economy
When Backpageâs credit processing was pulled (AMEX, VISA, Discover, Mastercard etc), Paxfulâs Local Bitcoin-like exchange stepped in. The wonder of this is that the girls who sell their escort services on Backpage, are rarely in a position to pivot with regard to the way they earn money. Simply, they are captured by whatever payment mechanism Backpage mandates. So suddenly, these girls needed Bitcoin. A similar phenomenon happened years ago when the Silk Road encouraged users to buy drugs online with Bitcoin. Drug addicts couldnât use their credit card or cash, for that matter, to buy their poison, they needed Bitcoin. This sort of necessity of use has begun to usher in a new era in Bitcoinâs history, where peopleâs ideologies are no longer the sustaining force. Bitcoin is seeing the development of a circular economy. And this, I would assert, is the point at which a naturally occurring Ponzi leaves the orbit of Ponzi-planet and enters the outer space of important utility. It is a thing people NEED, and not just a thing people speculate on. Iâm not an academic, so Iâm sure there is a lot of nuance that Iâm missing here. But this is an important distinction between Bitcoin and other blockchain tokens. There are plenty of other criticisms, like Poelstraâs critiques of non-proof-of-work (POS) coins, or the possibility of the existence of 2 proof-of-work chains. These are important, but tangential, technical debates. In this article, Iâm going to focus on the fiduciary side of the blockchain critiques, which I think we regularly ignore. And Iâll do it by giving my version of some history that many of you might not have been around for. I guess, in some ways, itâs a bit of accidental Gonzo journalism. I have always been a part of the Bitcoin story. And I can only really tell it from my perspective.
Bitcoinâs earliest mark of distinction is in its rise and rise. From having no articulated value to its famous, and sudden rise to over $1,000 in what seemed like no time at all in 2013. This is following subsequent sudden rises, such as the one that occurred right after Chuck Schumer declared that children could buy drugs on the internet. Shortly after, Bitcoin peaked at around $30 and suddenly dropped back to just over $1. Amidst the crash, Wikileaks declared that it was going to accept Bitcoin for donations.
Dumpy Butts and Fancy Shoes⊠the Beginning of Everything
There is little doubt that the rise brought with it a wave of speculators. Everyone everywhere heard the news of the once-cheap asset that had made its early adopters ungodly sums of money. Mere weeks after Bitcoin had hit $1,000, the North American Bitcoin conference was underway in Miami. Chris DeRose and I made our way to the event, one of many we would attend throughout the years. There, as Bitcoin hovered around $850, I was astounded by the newly minted millionaires of the ecosystem. Bitcoin had been priced between $7 and $14 not less than a year earlier. It had hit $100 around August. And by January had increased 8-fold.
Yet, there, on stage, a venture capitalist declared that he was an old-timer. âIâve been in Bitcoin since it was about $100,â he said. âIâve seen the ecosystem really evolve since then.â
The irony struck me. Everyone here wants to be an early adopter,I remember thinking to myself. While Chris and I had put in our time, we had been watching and playing with and talking about Bitcoin since before Schumer. We were here before the NPR reports. We had paid our dues. And here we were, hearing that old-timer meant arriving only 7 months ago. Whatâs more is that to date, I remember feeling like I had come to Bitcoin late. I had never thought to call myself an old timer. I felt like I had missed the early days having come around right after Laszlo had bought the Bitcoin Pizza for 10,000 BTC. And here, on stage, a Venture Capitalist had the tenacity to declare himself an old timer.
The conference might have been one of the most remarkable conferences in the history of the space. The rise of Bitcoin had given a number of people enough money to make the flight from wherever they were. The chairs were replete with 16 year olds dressed in new, odd, but very expensive clothes. Ridiculous Givenchy shoes, Armani suits, or clothing that could have at least passed for it, adorned the backs of everyone in the conference who had, just weeks before, never needed to cope with the trappings of wealth. Whatâs more, for those that could reflect honestly, many of their earnings had come from the change they had kept around after purchasing drugs on the Silk Road or other darknet markets.
The fevered pitch of anarchic dilettante was pervasive. We all discussed ending the fed, the evils of inflation, and we generally agreed that our purchase of tickets had landed us on this or another watch list of sorts. At the conference Vitalik Buterin, a young boy around whom there was no mythic glow, took the stage and described a system he was working on called âEthereum.â A group of developers who had put together a project called colored coins did a presentation, as did Neo & Bee. Charlie Lee took the stage in another room and discussed Litecoin, what people at the time referred to as the silver to Bitcoinâs gold. And then there was the special guest. Bernard von NotHaus, creator of the Liberty Dollar. He was in between his trial and sentencing, and had made the trek to Miami to be a secret speaker. He made brazen challenges to the feds whom he said he was certain were in the room watching him and us. But his speech had almost nothing to do with Bitcoin, and amounted to little more than an anti-government screed lauding the Libertarian mentality steeped in the likes of Bastiat, Hayek, and Mises. At this point, I was familiar, and even excited about the underlying assumptions: there is good money; there is bad money; gold is good money; government taxes are theft.
The party that evening was a festival filled with pretty girls, surrounding a dumpy, tall man whose pants didnât fit very well around his butt. He commanded a group of people as he spewed what sounded like nonsense. He was touting his new bank-killer Bitcoin-like app called Bitshares. I remember being completely perplexed by the marketing. It seemed like they had a ton of money, and I couldnât figure out exactly what it was, but it smelled fishy. Was it a Bitcoin bank? Was it a different blockchain? No one who heard the pitch knew. But everyone seemed to think it was going to make them some money. Since then, I think that most of us have become very familiar with Bitshares. And I think this is where our story begins. Because reflecting back on this conference, I think I realize that this is where much of the modern narrative about Bitcoin began, and this is where everything went wrong⊠and right.
Before the conference, scams and schemes had abounded. The pirateat40 Ponzi scheme, Tradefortress and his/her problems, Bruce Wagner and the MyBitcoin.com theft, Bitcoinica, and many many smaller schemes had all come and gone. Some of the problems with getting money into Bitcoin had been solved by Gox and Shremâs BitInstant. BitStamp had come around. Coinbase came around. And the market started to mature. To date, however, most of the scams had been Bitcoin-based. There had been a few alt coins launched including Litecoin. But they were mostly an afterthought. At the time, no one really knew what this thing was. We were all pretty convinced that altcoins had a place in the ecosystem. I remember even discussing with Chris the possibility of setting up endpoints around town at Starbucks coffee shops and using their internet to mine TorCoin. This is a fact I am a bit embarrassed to admit, but I think that it would be imprudent to wash my own history here. TorCoinâs proof of bandwidth consensus mechanism is (Iâm sure) as stupid as it sounds. But back then⊠how could we have known?
And thatâs what happened to everyone. People showed up, they looked around, and they were struck by the magical superpowers endowed to anyone with a penscient for the Dunning-Kruger complex. I summed it up years later, with the now well-used Bitcoin meme, âI Just Heard About Bitcoin⊠Iâm Here to Fix It.â

This is the mentality of everyone who looks at Bitcoin. Itâs a large, inefficient data structure, that requires massive amounts of energy to be burned in order for it to work. All of this happens to be for very good reason. In fact, I might go so far as to say that Bitcoin is big and unwieldy for the same reason that government is big and unwieldy. The problem it solves, the Byzantine Generalâs problem, is a corruption problem. And, as any regulator will tell you, the way to do deal with corruption is to develop massive infrastructures for rooting it out. Bitcoin is the un-regulated example of this. Its infrastructure costs are a softwareâs version of compliance costs. But those inefficiencies, to a newcomer, look like opportunities. And while, I think, simple abstractions like this one can get ridiculous, this is the closest Iâve come to making the necessity of the inefficiency of a blockchain simple to understand.
Larimerâs Moonshot and the Beginning of the Miami Bitcoin Meetups
When Larimer, the man with the dumpy butt who commanded attention for Bitshares back at The North American Bitcoin Conference, launched his blockchain it was the beginning of a new era in Bitcoin, I think. When Bitsharesâ blockchain launched, the price began to rise. Up and up and up it went. What it was for, nobody really knew. All anyone would say is that it was a better, newer version of Bitcoin. Bitcoin was the old Model-T, Bitshares was a new shiny Ferrari. It rose to a value of just under $90 million in short order. Other coins, at the time, had reached impressive heights. Doge Coin had a much vaunted rise not so long before this, AuroraCoin was apparently worth $367 million in March of 2016, and there were numerous other coins that had made a mark on the ecosystem. But none had seemed so cultish to me as Bitshares.
It was around this same time that Chris and I began running the South Florida Bitcoin Meetups. It was our first real view into the Bitcoin ecosystem escaped from the insularity of our shared office space. We had new Bitcoiners coming every week, and we noticed that all of them would follow the same journey. They would come to get rich, asking questions about mining. We were uneducated in the subject of mining, but were pretty sure that it was not a good idea based on our having seen hundreds of people lose their shirts trying to build mining operations. It is largely unknown that DeRose and myself had strongly considered mining Bitcoins back in 2012, though we had decided against it (thankfully). We would have the occasional miner show up, and they would tell us all about their setup. The local hobbyist miners were always the most arrogant. And they always seemed to know the least about the subject matter.
Then There Was JamesâŠ
James was a Bitshares believer. James was a family man. James had a wife, a kid, and was doing his best to provide for them. James got sucked into the Bitshares phenomenon, each week coming to the meetings giving us updates about the Bitshares blockchain. James was a programmer, and James knew what blockchains were. He was a competent coder who always had a strange side-project. His schemes were always hair-brained attempts at making money, but they were always pretty impressive as far as the technical abilities they betrayed. The week that Bitshares popped and rose from a tawdry market cap of around $16 million to its height of $90 million (August 15, 2014-August 26, 2014), all the believers went out and did the same thing that the Bitcoiners did at the end of 2013.
The next week, when James showed up at the next meeting, he had a new shirt on, new pants, and new shoes. He hadnât overdone it like the 16 year olds. He was a family man after all, more risk averse. But he was given to the same proclivities to spend his gains as his 16 year old counterparts, just a bit more tempered. âIâm moving to North Carolina,â he told us. He had been hired by Bitshares to work full time on their code and he wanted to be nearer Larimer and the team. He was to be paid in BitUSD - Larimerâs attempt at a simulated federal reserve that, through a decentralized market, would peg the value of the coin to the USD. The project was soon to launch. And, while ridiculous, was one of the first attempts at what has come to be known as a âStable coin.â It was on a different blockchain than Bitshares, which by this time had become a bit of a blockchain fart factory, and was the kind of idea a child might have.
Needless to say, James packed his bags and left for the hills of North Carolina with his kid and his wife. I donât know what happened to him. I hope heâs doing well. But somehow, as he was a believer, holding on to his coins for dear life, no matter what the evidence would have otherwise suggested, I imagine he has ridden Bitshares from its peak valuation of nearly $90 million, all the way back down to its current value, hovering somewhere around the still surprising market cap of $12 million. At the very least, itâs back to where it was when James couldnât afford the nice new shirt, shoes, and pants. But with it, I imagine, James probably purchased a lot of Bitshares all the way down. Somehow, while I hope heâs doing okay, I imagine that life for James is significantly harder now than it was when he was earning money from his blockchain programming.
Larimer Exits His Ponzi and Turns it Over to the Community
Nearly one year ago, Larimer announced on Letâs Talk Bitcoin, that he was abandoning the Bitshares project, and turning over the blockchain to the community. His team was moving on to an even newer project, a sort of Bitshares 2.0. Now, not so long after the initial launch of the Bitshares blockchain, it seemed that Larimer believed the original project was the new model-T of crypto. The move was unprecedented. Consider if you will, the fact that the investment in Bitshares was largely an investment in the team that created Bitshares. Larimer was who people were betting on. And for those that rode the rise in price, Larimer is still lauded as a man who can truly return value, though everyone will acknowledge that attempting to make money on the rise was a bit like trying to catch a falling knife. In his interview, as Levine points out, âthis is the 3rd or 4th reinvention of the project.â Though Levine lacks the ability to understand the obvious fact of the matter: Bitshares was the first mass exit of what is probably a legal Ponzi scheme built on the back of information asymmetry.
Larimerâs team released a feature list that they said made their blockchain different from Bitcoin. And sure enough, the feature list was and is very impressive. Those who look at it will certainly acknowledge that Bitshares, on paper, is the Ferrari to Bitcoinâs Model-T. But the difference is that while Bitcoin was created in a world of 0 blockchain alternatives, Bitshares was created in a world of at least 1 alternative. The only way to purchase Bitshares and its subsequent experimental tokens like BitUSD, was to first go through Bitcoin. So it stands, that even those who wanted to purchase Bitshares, like the girls of backpage, they needed Bitcoin. Though unlike Bitcoin, no one needed Bitshares. Moreover, despite having an impressive feature list, Bitshares had plenty of other problems going for it such as its reliance on a nonsense non-work based consensus mechanism - which was its biggest feature. But like my admission that I had been taken for a ride by a proof of bandwidth based consensus, for the lot of us who were new to blockchains, how could we possibly have wrapped our minds around the claims back then? Dunning-Kruger is a disease of the human mind.
The astounding thing about these non-Bitcoin blockchains was the temerity of the believers to accept all claims without question. While Bitcoinâs solution to the Byzantine General problem was its reliance on simple, elegant Proof of Work, a young, barely 20 year old man, came along and claimed that he had also solved the problem using no work - perhaps the hardest problem ever solved in computer science. Throw in âconsensus mechanismâ and it was enough to draw in anyone who loved Bitcoin but who also had in their ideological framework an important place for environmentalism. Those with such a complex agree (even to this day) that Bitcoinâs proof of work is wasteful, and that we should, at all costs seek out alternatives. But the claim is to utterly misunderstand the process of proof of work. And as proof of stake (as the Larimer alternative has come to be known) has gained a foothold in the architecture of every subsequent blockchain, the criticisms of the most competent people in the room have been realized time and again: namely, all consensus mechanisms revert to work and as such, POS is nothing more than the process of obfuscating the process of that reversion. And thusly, with each new iteration, the proponents of proof of stake demonstrate the farthest reaches of the Peter Principle wherein a person obfuscates to their degree of comprehension. When there, they cease to be able to see the problems and all things are suddenly reducible (more on this later).
The Anatomy of Blockchain as Ponzi
The Ponzi scheme represents a belief in perpetual motion. People will invest in obvious Ponzis because they believe that this time, itâs different. This time, the Ponzi will go ever up and never down. But as the World Bank said, âThe catch lies in the fact that there is no stopping point. Since old investors get paid with the deposits made by the new investors, you need an ever-growing pool of investors. This cannot happen endlessly in our finite world. So the tragedy of the Ponzi is that it has to crash.â Alas, the deeply seated belief of the investor in pyramid schemes of these sorts is that the inflows will never end. It is the perpetual motion machine of finance. Likewise, the belief that blockchains can work without power, which was what Larimer set out to do, is a claim equally as absurd as saying a Ponzi will continue to grow forever. It is a mechanical engineering claim that the worldâs biggest problems are reducible to systems with no opportunity cost. And so it goes, the mentality of Ponzi investors and the mentality of blockchainists are the same, just in different realms.
Consider that the entire history of Bitshares was controlled by a single person. Larimer had all the information about when features would be released, announced, and, more importantly, when he was going to announce his exit from the project. He was in full control of when the inflows of money would suddenly be made less attractive. The dirty secret is that no one ever used Bitshares. Almost all of its funds were kept near at hand, where individuals could sell in exchanges. No one ever knew whether the features promised by Larimer ever worked. As such, the entirety of the value was based on the speculative interest in the feature set and Larimerâs ability to develop that feature set. For those that were competent enough to actually use Bitshares, they will tell you that the blockchain and its software have never really worked at all. None of what was promised was delivered. But it didnât matter anyway, since no one ever needed the Bitshares blockchain. And so, filled with regret, Larimer was able to do whatever he wanted with his funds before making announcements about the project. While I have no evidence he did it, I can only assume that he and his team regularly bought before feature announcements were made, and sold before events like Larimer announcing his exit. The small team of developers were completely in control of the speculative inflows and completely aware of when those inflows would stop. And when they stopped, the team walked away from the project. And as the project slowly collapses on the believers, the team will be able to say very simply that when they left the project, everything was a-okay. And the guidance of the community that took over its development is how their blockchain lost its way.
This is the nature of blockchains. Insofar as we can agree that they are (somewhat) organic structures, built on the backs of faithful participants who host them on their computers, before a blockchain develops a circular economy it looks very much like the World Bankâs description of a natural Ponzi. And insofar as this organic structure can be conjured up in the same way a seed can be planted by a person and gives rise to a tree, a team or an individual can direct the growth and subsequent downfall of the blockchain Ponzi with little to no legal ramifications. Larimer did it with Bitshares. Heâs doing it again with an even more sophisticated version of it now in his promotion of Steemit, a blockchain that solves all the problems Bitshares was plagued with - at least thatâs his claim. The feature-list of Steemit, hilariously, is its Ponzi-like illiquidity mechanism which prevents users from exiting their position by locking up their funds with a promise of big returns. But this time, itâs different. This time, they will tell you, the inflows will never stop. Right?
Enter the BankersâŠ.
(To Be Continued)
A Step By Step Plan for American Bitcoin
By Beautyon
Posted January 27, 2017

Now that America has a pro America president that is minded to put America first in all matters of trade security and prosperity in the form of Donald J. Trump, we have some suggestions as to what the American government should do to make the USA the center of all Bitcoin commerce, research and development and profit.
We say, like other market actors that no new laws are required for Bitcoin. If Donald J. Trump delivers on his âtwo laws out fore every new law passedâ and all Bitcoin regulation is eliminated, Bitcoin services will spread all over America and eventually the world, as everyone follows Americaâs lead.
Step 1
Make America benefit from digital currencies Bring the significant benefits of the software to the US market, to the advantage of different groups i.e. consumers, businesses, government, and the wider economy.
In order to achieve step 1, the true nature of Bitcoin which emerges from tools built from Satoshi Nakamotoâs basic innovation, âThe Blockchainâ needs to be clarified.
The distinction made by unnamed people in the government, who consider that âVirtual Currenciesâ differ from âDigital Currenciesâ is a false one. The fact that what are described as âVirtual Currenciesâ are issued and usually controlled by their developers is no different to âDigital Currenciesâ. Both of these products are software, engineered by software developers.
In the case of Bitcoin, the virtual community and control of it is global it is not constrained to a single domain, person or company. In the case of Linden Dollars used by Linden Labs in their proprietary game Second Life the virtual community and control of itâs currency are constrained to interactions on servers under a single domain. The use of the software in both of these contexts is for all intents and purposes identical; it is _an economic simulation_and there are several of these currently active (1). The scale of the simulation is irrelevant to the nature of the activity and how it should be defined. Bitcoin is usable only inside and between the members of the specific community of Bitcoin users, the same way that Linden Dollars are only usable to the people who are members of the virtual world created by Linden Labs.
You cannot say that Linden Labs is beyond the scope of this call for information, without explaining precisely why Linden Dollars are different from Bitcoin; they are not, save in the manner that the transactions are recorded and the scope. The nature and purpose of the two systems is identical; the recording of who owns what arbitrary token that is redeemable in a closed system.
By the act of a government asserting an artificial distinction between Virtual Currencies and Digital Currencies, it would be impossible to make a businesses case for Linden Labs to switch the software running its in game currency to Bitcoin, which is more efficient, removing much of the management and security of Linden Dollars from Linden Labsâs servers. If the government regulates Bitcoin, moving from a less secure model to a more secure one would expose Linden Labs to arbitrary regulation. Making people less secure should not be the aim of the government. This side effect is true no matter who the company wishing to use the Blockchain is, whether it be a game developer or a company providing another service.
The benefits of The Blockchain and Bitcoin are many, and are only just beginning to emerge. The Blockchain is a distributed programmable database, and it is this that will be the subject of any regulation. You cannot regulate Bitcoin alone, and it cannot be separated from the function of the Blockchain. Saying, âI like Blockchain technology but not Bitcoinâ is completely irrational, and people who say this betray a deep computer illiteracy.
There are many software developers working on unprecedented applications for the Blockchain, and in these very early days, it is impossible to predict what these innovations may yield. Five years into the beginning of the modern Internet, YouTube did not exist. No one in the 1990âs would have been able to predict YouTube in its present form. The same goes for Twitter and every other âWeb 2.0â service that is now live. It is therefore almost impossible to predict what the business models and the benefits of digital currencies and the Blockchain will be.
What we can say with absolute certainty, is that the potential benefits, given only what we can imagine now, will be highly significant. Any new tool or software that saves time and expense across the entire economy can be said to bring significant benefits, and this is what Bitcoin will do at a minimum.
For consumers, micro-payments in pennies are now possible, changing the way online content is paid for on a global basis. This will mean businesses can charge for services in ways that were previously impossible, because the means to move tiny amounts of money used to incur charges that made micro-payments uneconomic.
Local Government will also reap the benefits of Bitcoin, by being able to charge for services in a fine grained manner. Parking is just one example; it will be possible to charge for parking in a way that eliminates the need to collect cash from machines, without requiring Credit Cards and their astronomical fees. The uses to which Bitcoin will be put are as varied as all economic activity.
As for how the benefits vary according to different digital currencies, this question presupposes that there is a difference between the digital currencies. There is no difference. Each of the various âcoinsâ that are derivatives of the original Bitcoin source code are carriers of money in the money substitute context; Bitcoin is not money in and of itself. Each of the different âcoinsâ have a capacity to carry the same amount of money; the only variation between them is the ratio of the amount of âcoinâ to the amount of money held by it. It is an arbitrary number in every case, determined entirely by the market, and this is the measure of the utility of each âcoinâ. How many people accept it, what software has been written on it, etc. is what matters.
Step 2
Ensure the government does not intervene to support the development and usage of digital currencies and related businesses and technologies in America. If the government should not intervene, and it should take no action other than enforcing existing basic consumer law.
The government should not intervene to support the development and usage of digital currencies. What it should do is declare a 150 year moratorium on legislation that touches any individual or company that is engaged in the buying and selling of digital currencies, or that engages in the development of any software that touches it. The hands off approach in this rapidly emerging sector can be absolutely guarantee American dominance by a moratorium on new law or regulation, which is already a part of the Trump/Pence platform.
Britainâs 150 year lease on Hong Kong is the model to follow. Sitting next to Communist China, the low tax, low regulation island of Hong Kong was a showcase for how an economy should run, thanks to British foresight. In the digital era, when companies can incorporate in any jurisdiction, America must make itself attractive to entrepreneurs if it desires to be the number one destination for businessmen to base their Bitcoin businesses. Even today, innovative consumer Blockchain companies like Brawker (2) are incorporating in Hong Kong, despite its return to China.
If you do not take this measure, all of the Bitcoin start-ups will avoid the USA as they already avoid New York and its infamous âBitLicenseâ. Skype, the globally popular internet telephony company incorporated in Estonia (3), not America. This will happen again, and America will miss the boat in the digital currency revolution that is beginning right now.
Lawyers will insist that there need to be laws specific to the Blockchain and Bitcoin, but this is a mistake. There are sufficient laws on the statute books to cover every imaginable Bitcoin dispute, and of course, the Blockchain makes possible all manner of new forms of enforceable contract. The only special interest that is relevant here is the interest of America itself. By allowing Bitcoin companies to flourish in America, the US will benefit across the board. This should be the ultimate aim of the Trump government, and a moratorium on regulation will effectively achieve this.
Remember also that all Bitcoin businesses that incorporate in the USA will be paying corporation tax on the hundreds of billions of Bitcoin transactions that they will be processing. Those transactions can be processed in any jurisdiction. This is a matter of the most grave importance to the future place of America in the global economy. We want the USA to be at the centre, and the only way this can happen, is if entrepreneurs are left free to innovate here.
Step 3
Do not regulate digital currencies, no matter which types of digital currency is on the table. Do not create bespoke regulatory regimes; existing laws are sufficient. There are inevitable unintended consequences of regulating, and it is un-American.
The Federal government should not regulate digital currencies. In order to understand why I am making this assertion, you need to understand what a digital currency is with precision.
Digital currencies are pieces of text moving over the internet. They are nothing more than text, and they are always text. If you believe that you can regulate digital currencies, then there is no reason why you cannot regulate Tweets on Twitter. Tweets and Bitcoin transactions are indistinguishable from each other save the context in which they are displayed. The Blockchain in the context of the money use, Bitcoin, appears to be a form of money, but it is not. It is this profound confusion that has triggered much discussion and so much government attention; if that were not the case, a review would have been called to ask whether or not Twitter users should come under a bespoke regulatory regime. No American in their right mind would suggest such a thing, since its blatantly anti-American, but these same people also cannot say with precision why Twitter is different to Bitcoin.
The current misunderstanding of the Blockchain is being promoted by a small group of people who make their living off of the side effects of regulation. It is in their interests to see that Bitcoin is regulated; it will mean that they can specialize in consultation, association, certification and licensing of Bitcoin start-ups and charge fees for their services. These people do not have Americaâs best interests at heart; they only want to profit from the imposition of regulation. Software developers on the other hand, do not have an interest in regulation. They have their users best interests uppermost in their list of priorities. Regulation will only harm developers by causing them to move their operations into different jurisdictions. Developers and America have common cause in this respect. America must not imitate Blockchain-hostile jurisdictions like the UAE.
The unintended consequences of irrational regulation, quite apart from creating barriers to entry and huge, unnecessary compliance costs, will be the creation of classes of software that completely exclude the government from participation in Bitcoin and sectors of society. This new software will not come exclusively from individual hackers, but will emerge from multi billion dollar corporations like Apple and Google.
Apple have just released iOS8, which explicitly excludes the security services from being able to access iPhone user data. The built in military grade encryption in Appleâs FaceTime and iMessage tools are good examples of how companies will react to Bitcoin regulation. FaceTime calls and iMessages are encrypted and cannot be deciphered by anyone other than the sender and recipient. Google has made changes to its Android software to offer similar protections. As Bitcoin grows, it is absolutely guaranteed that Bitcoin clients will be added by default to all mobile phones, just as email is now included by default, alongside voice calls and texts. These companies will build Bitcoin into their offerings in a way that will completely exclude access by government. This cannot be stopped and is inevitable, but what the government can do is profit from the transformation, by making their jurisdictions Bitcoin attractive.
Apple, despite locking out the government from its phones, is making billions in profit that is not being repatriated. If the economic conditions are correct, Apple will bring their money and manufacturing home, but government will never again be able to break into peopleâs phones. Where those phones are made is not relevant; this is the new reality that is not going away, ever. Its better for America to profit from this new reality, rather than lose access to everyoneâs communications and lose the tax revenues from the sales of these devices.
If the beginning and end points of all Bitcoin transactions is Brooklyn, then America will reap the benefits of hundreds of millions of dollars worth of transactions. It will also reap the benefit of software developers being in high demand, and the training needed to bring them up to standard. The knock on effects and consequences will be many, and each will be a multiplier for the other. What we can say for sure, is that the possibility of this happening in America will be destroyed if there is another country, a better country, where entrepreneurs and developers can put down roots with guarantees that their work will not be artificially hampered.
There are other side effects of the Blockchain which must be understood fully to make a proper determination of what is and is not rational or even possible in terms of regulation.
Multi Signature Transactions (4) (Multisig) are transactions that require the consent of more than one key holder. This makes possible transactions that take place entirely on the Blockchain, without a merchant needing to âreceiveâ and âstoreâ Bitcoin in its locally controlled wallet as if it were performing a money function simulation. I put the words receive and store in quotes because these two acts never actually happen in a Bitcoin transaction.
The website Purse.io is a perfect example of this. Purse.io is a service that puts together owners of Bitcoin with Credit Card holders. If you want to buy something from Amazon (that does not accept Bitcoin), you can use Purse.io to find someone who will buy the goods for you with their Credit Card, and you pay the buyer with Bitcoin. Purse.io acts like a match maker to facilitate the transaction.
In the Purse.io system, Bitcoin is never transferred to them directly for storage. They instead, use a Bitcoin Multisig Transaction to âstoreâ the Bitcoin on the Blockchain. When the goods are delivered, the buyer signs off on the transaction, and so does Purse.io (a âtwo of threeâ transaction) and the Credit Card holder receives her Bitcoin. Purse.io describes it in this manner:
âWhen you create an account at Purse.io you are not required to deposit any bitcoins. Instead, your funds will go through a multisignature address controlled by at least two of three different keys. The Bitcoin spender receives a key, the buyer has the second one and Brawker the third key. Two keys are required to transfer the funds. You control your private key, securing it with your password. What does this mean? That the funds involved in the transaction are not controlled by Purse.io, but by the two parties to the transaction. Purse.io intervenes only to settle a dispute.â- Purse.io
In this scenario Purse.io does not take charge of any Bitcoins and is never in receipt of them, or any money; it acts only as a match maker. No financial regulation can possibly apply to them, even if a legislator mischaracterizes Bitcoin as money; Purse.io never takes control of the Bitcoin used to purchase any goods.
Multisig transactions like this ensure that all the actors are honest, and it removes the need and risk of vendors taking control of Bitcoin as deposit holders. The Blockchain acts like a Silent Automated Guardian over transactions; completely neutral, provably honest. No money changes hands, even if you wrongly believe that Bitcoin is money.
This is only the first of many new possibilities that are beginning to emerge thanks to Bitcoin. Clearly legislation cannot take into account the myriad ways software developers and entrepreneurs are going to leverage the Silent Automated Guardian that is Bitcoin.
In the above real world example I just cited, which entity will the computer illiterate claim should be regulated? The Credit Card company and seller are already tightly regulated and operating normally. Purse.io cannot be regulated since it does not accept Bitcoin, goods or money, and is only a match maker without any power over or part in the transaction. Bitcoin network itself is not a legal entity, is everywhere, not in a single jurisdiction and cannot be regulated for that reason alone, quite apart from it being a mere ledger.
Not even the most ardent, strident proponent of âBitcoin as a threat to civilizationâ is suggesting that every owner of Bitcoin should be licensed, which is the only option left in a Multisig world. Purse.io proves that it is possible to create a service that cannot be regulated at all in the current rules or outside of them, since none of its constituent parts can conceivably fall under any statute.
Finally when incorporated in Hong Kong, the US governmentâs position on companies like Purse.io is completely irrelevant. The government only has a say in what companies do if they decides to abandon Hong Kong and move to Hartford Connecticut, which if the government makes the wrong move re Bitcoin and Blockchain businesses, will never ever happen.
Step 5
Remove all barriers to digital currency businesses setting up in the USA, starting with New Yorkâs BitLicence under the Trump âtwo out for one inâ deregulation programme, and signal that no action should be taken by any Federal or State government to regulate Bitcoin businesses above and beyond normal law.
There are no barriers to anyone starting a Bitcoin business. Anyone can start a Blockchain or Bitcoin business and then put it on the market. This is exactly as it should be, and the biggest and greatest of all Bitcoin companies, Qkos, the UK incorporated creators of_âBlockchain (*5*)â_, the nearly perfect Bitcoin Wallet for iPhone and Android is a fine example of this.
Qkos is now the biggest provider of Bitcoin wallets on Earth. Their software offering is highly innovative, in a way that many others are not. Qkos demonstrates exactly what Bitcoin entrepreneurs are capable of producing, and we can expect more of this sort of innovation coming from America if the Trump government takes the long view and commits to a multi-generation moratorium on any legislation that touches Bitcoin.
Step 5
Unleash the highly signifigant benefits of this distributed ledger technology by forbidding regulation.
The Blockchain is not just a platform to facilitate a new form of money, or digital barter or bearer instruments, or investments as the non software developer will claim. The Blockchain is a way (amongst many other things) to identify that someone owns something, without having to rely on a third party.
The databases used by DMV, Birth and Death Registries and any other registry that is centrally administered can be entirely replaced by Bitcoin. The potential benefits of this are many. With Bitcoin as the backbone, it becomes impossible to forge owner registrations once they are made. There will be significant savings across the entire economy as people use Bitcoin to pay for and verify registrations. The distributed ledger that is infallible, incorruptible, public and secure changes the way anything can be certified to be owned; it is the ultimate arbiter of titles.
Clearly there are potential benefits to government, but the software applications that will bring these benefits needs to be written. They can either be written in London, or San Francisco. Look at this from the British perspective. For decades the UK government was forced to use Microsoft Windows and its âOfficeâ suite because, everyone was repeatedly told, âits is the standardâ. This American software, with all its many flaws, including built in surveillance, could have easily been replaced entirely with a 100% British equivalent, had a software company capable of writing one been encouraged to start in the UK. Now, the Open Source Libre Office (6) is slowly replacing Microsoft Office, and Windows is being replaced by GNU/Linux (7) globally. Bitcoin will take root in another jurisdiction and eventually make its way to the USA via a foreign company; this is absolutely inevitable, unless the companies are started in America.
Ultimately, the benefits of distributed ledger technology are as a firecracker fuse to ignite the American Bitcoin Revolution. America has the talent, which is the crucial element.
Step 6
Properly categorize the risks digital currencies pose to users, realize they are not significant. Allow the market to pick the winners and the law to punish fraudsters.
There are risks in any software that is exposed to users. Microsoft Windows has exposed its users to serious risk for decades, and to this day, millions suffer from Trojans and Viruses, foreign corporate espionage, theft from bank accounts and Credit Card accounts and other invasions of computers, thanks to the Windows operating system. Nevertheless, the information economy boom has managed to transform how everyone in America communicates and works and even shops for their groceries despite these acknowledged flaws.
Bitcoin users will encounter problems, just as users of Microsoft Windows do, but none of these problems are as massive and society changing as the benefits brought by the software. The Blockchain technology itself is secure. When used on a platform that is secure (iPhone using the Blockchain Bitcoin App, or Multibit (8) on a computer running Linux) the risks are far lower than those associated with entering your Credit Card details on a web form in Internet Explorer, or doing online banking on the Microsoft Windows platform.
This is the correct way of characterising the risk associated with digital currencies. There will always be risk, but Bitcoin completely eliminates a large class of risk, making their adoption an obvious choice. âCard-holder not present fraudâ in Credit Card transactions is widespread. Readers of this article will be aware that there are markets where Credit Card information is sold to fraudsters. Bitcoin will eliminate this activity entirely. Target (40 million users compromised)(9) and SONY (77 million compromised) (10), to name but two, had over 100 million Credit Card details copied from their servers. With Bitcoin as the payment method this is absolutely impossible.
Bitcoin will make the theft of Credit Card information a thing of the past. No one will ever again be the victim of charges on their Credit Card made by a criminal. The savings from this side effect of Bitcoin alone will be measured in billions. All of the effort put into securing Credit Card transactions will be abandoned once Bitcoin is the default way of buying online; this is because all the transfers in Bitcoin are guaranteed to have come from the person making the order. Bitcoin completely eliminates payer fraud. A Bitcoin accepting businesses therefore, has no need to perform the expensive checks and automated anti-fraud procedures that plague Credit Card users today, all of which will seem like the most absurd antiquated nonsense in the Bitcoin world.
The inevitable legal risks that will emerge when a billion people are using a single technology can all be dealt with by existing legislation. Fraud is fraud, whether it is done by merchants accepting Bitcoin or any other form of payment. When a merchant makes a promise to do something under contract, that contract is not invalidated because he is being paid in Bitcoin. An understanding of basic legal principles and Americanism is crucial in forming a correct opinion on Bitcoin, as much as is a correct understanding of what Bitcoin is.
Step 7
The government should not intervene to address the risks of Bitcoin, and should quickly press on with removing any law that could impact it. Taking no action specific to Bitcoin is the correct approach; the market and existing law will be able to address these risks itself.
If the Federal government intervenes to address imaginary risks, it will be a monumental and corrosive mistake. First of all, there is no way of knowing what the true risks are, since the form of future software developments that will automatically mitigate those risks is un-knowable. A perfect example of this process is Multisig.
Multisig transactions require that more than one person approve a Bitcoin transaction before it takes place. These transactions will be useful in new forms of letters of credit, and other instruments that do not yet exist. The government cannot regulate what does not exist, or what it does not understand; and I do not say this to imply that the Federal government cannot understand the impact of these applications; no one does, because the applications are only just beginning to emerge as possibilities and potential in alpha stage software.
The status quo now is âheads down and keep at itâ. Developers and entrepreneurs are racking their brains, risking time and money trying to make things that no man has imagined. They do not need to be disturbed by threats of regulation and legislation that will cripple and block off the fruitful directions they want to take their imaginations and software.
The market can most definitely manage, mitigate and solve any risks itself. Multisig Transactions are a very good example of this. When millions of pounds worth of Bitcoin are sitting in a single company account, previously any man with access to the wallet could have transferred the Bitcoin to any address. Now, if that Bitcoin is in a multi signature address, a majority of the directors (for example) must approve any transaction from that wallet address. It will be provable that they approved the transfer to a standard of proof which will hold up in a court of law. This is a remarkable innovation in corporate transparency and responsibility, and it has come about without the direction of government; it was done because it is in the best interests of Bitcoin companies.
If the Federal government had intervened earlier in Bitcoin, Multisig might not have emerged, as developers and users would claim that they can always rely on the FDIC to make good any losses. Intervening by the Federal government now in the early stages of Bitcoin and the Blockchain will prevent future tools like Multisig from being developed, at least in America, which will ultimately harm business and consumers by making Bitcoin activities less safe.
Step 8
The government should not regulate digital currencies to protect users. It should not create bespoke regimes, and should regulate through an existing fraud law. There are many possible unintended consequences (for instance, creating a barrier to entry due to worthless compliance costs) that will kill Bitcoin businesses in America and move them off shore. The Federal government should rely on the free market to regulate Bitcoin.
I quote from the British governments â5 reasons weâre calling for information (about Bitcoin)â page:
âThe safety net of a regulator can give firms the assurance they need to start up in the UK and ensure consumers and businesses are protected.â
The government cannot give assurance to firms in any other way than the promise that they will not be regulated or interfered with. It has no expertise in software, and in fact contracts out all of its requirements in that area. They are not in a position to make a judgement on what Bitcoin business or tools are sound, and there is nothing wrong with that; Microsoft Windows is a perfect example of a completely unregulated and fundamentally flawed software service that is immensely beneficial to society globally.
The government cannot protect users through regulation, and neither can it provide a safety net. The US government could not make whole the people wiped out by a banking crisis through FDIC, and it will not be able to make whole anyone hit by entrepreneur or developer error in Bitcoin. It is unethical to take money from the Federal government to replenish the wallets of Bitcoin users or entrepreneurs who make mistakes that are their sole responsibility.
If the government wants to indemnify and make whole Bitcoin users (who are essentially users of software), they must explain why they will not indemnify all users of Microsoft Windows from losses caused by viruses and the resulting theft of information leading to losses of any kind. You cannot make a case for certification of Bitcoin businesses without extending the logic to all software tools and developers. Bitcoin is not money, it is software performing money simulation as one of its many possible functions.
Bitcoin users are at risk in the same way that users of Microsoft Windows are at risk from being hacked. No legislation can stop a user of Windows from being compromised; if the aim of the government is to protect users, legislation and regulation are not the tools to do it.
To put it into context, millions of users of Microsoft Windows are compromised by viruses on a regular basis. This has been going on for decades, and yet, people still use this software, which is widely known to be extremely vulnerable, to do all their computing successfully. Anti-Virus software companies have built billion pound businesses (11) with the sole task of keeping Windows users safe. Bitcoin will be no different, and the measures to protect consumerâs Bitcoin will be developed as time goes on, probably by the same companies that specialise in protecting users of Microsoft Windows. Encrypting your wallet and using Multisig, or refraining from keeping your Bitcoin on a machine that is compromised out of the box will all reduce the consumerâs risk.
Then there are the devices like Trezor (12), and Ledger Wallet (13) from companies based in the Czech Republic and France respectively, which make dedicated hardware wallets that remove Bitcoin from the risk of Microsoft Windows and the attacks made against it. No government can predict what sorts of software and hardware innovations are around the corner, any of which might be made impossible to develop in Britain should the government decide to try and regulate the Blockchain.
Step 9
The government should ignore crime risks associated with digital currencies; they are insignificant compared to the benefits. The risks are the same with all software, not just Bitcoin. The free market and existing law should be used to control these software products.
The risks with Bitcoin as a tool in the commission of a crime are the same as the risks of any tool used in any human activity. The risks are remarkably low as a percentage of all the harmless, lawful activity. Presently, much noise is being made about the use of Bitcoin to purchase illegal drugs. Putting this into context can help us determine the proper position to take.
All over the United States, the prohibition era is ending. In 15 years time, there will not be a single state in which marijuana growing and consumption is not legal for all. In the future the Silk Road arrests will seem like the highest farce; America should not make laws now that impact Bitcoinâs development here, based on unthinking opinions and bad law that are widely held in contempt by the public and which are being dismantled globally.
America must look to the future, where these problems do not exist. Prohibition is ending; legislating now as if it will not ever end is not sensible, and does not reflect the reality of what is happening in society. Remember; the goal should be to make America great again, and the home of all Bitcoin companies and innovation. This means looking at the trends and planning for the future, not getting mired in todayâs hysteria.
The only risk associated with digital currencies is the risk of America missing the once in a century boat to prosperity and global influence. This is the most important factor, and distractions like this that absorb time and effort are not beneficial.
This question would not be asked about the internet itself, or computers or iPhones, all of which are used in the commission of crimes. No one would suggest that the makers of these companies should come under a bespoke regime because a statistically insignificant number of miscreants use their tools to commit crimes. The criminals committing the crimes themselves should be punished, not the ordinary users who use the tools completely innocently and normally.
Step 10
The Federal and State governments should not intervene to address these risks. There are vastly positive outcomes of taking no action, and only negative ones for trying to control Bitcoin.
Intervening in Bitcoin and the Blockchain should be out of the question. The Federal government should encourage Blockchain businesses to incorporate in the USA by guaranteeing that there will be no regulatory surprises in the long term future.
Software development is hard to do, and with many competitors all over the world, all working in the same space, it is difficult to deliver products that are not superseded overnight. In a jurisdiction where you are competing against other developers globally but also fighting the local government, precious resources are frittered away for no benefit to anyone.
America should provide a level playing field to developers where the landscape is guaranteed not to change. Entrepreneurs will settle here knowing that they are on the strongest possible footing to concentrate entirely on their product, to the exclusion of all else. This will cause the best products to emerge from America consistently. This will be the effect of a 150 year moratorium on any legislation that touches Bitcoin or the Blockchain.
The consequences of taking no action and leaving the bad laws on the statues are to risk that America might become the centre of Bitcoin activity, by luck. If the threat of legislation is always there, people will hesitate to invest in setting up a company in US jurisdiction. Why would anyone take the risk that five years down the road after four years and eleven months of development, an absurd âBitLawâ is to be introduced in America, killing innovative business models, forcing people to flee these shores? No one with any sense would take that risk. Entrepreneurs thinking rationally will opt for the best long term base, wherever that is, rather than risk being mired in a country where an anti-business government can spontaneously be elected.
Step 11
The Federal government should take no action to address the imagined and exaggerated risks of financial crime. It should immediately abolish bespoke regimes like BitLicense, and regulate through existing law.
Bitcoin is the same as any other tool; it can be used for good purposes and bad purposes. Bitcoin is not money, and so it cannot be used for financial crime in a way that is different from the exchange of any good or information in the moving of the proceeds of crime. This thinking is a distraction from the important central thrust of the Bitcoinâs nature. There are a few voices who will say that these questions are key; anyone with an understanding of the history of software will know that they are not.
America should not introduce regulation to try and control Bitcoin. If the Federal government introduces regulation, Bitcoin entrepreneurs will incorporate in other countries. The disadvantages regulation have been spelled out in other answers above, including the unintended consequences, the least of which is a barrier to entry due to compliance costs which can easily be avoided. This has in fact, just happened in Australia, with the Bitcoin company CoinJar.
The impact of the New York âFinCENâ on digital currencies has been to cause all Bitcoin businesses not run by Americans to strike America off of their list of possible bases. New York in particular is exceptionally toxic, since it is bringing in a local and absolutely absurd âBitLicenseâ that betrays a catastrophic computer illiteracy and misunderstanding of the Blockchain. America is a sovereign nation, and should only do what is rational and in its own best interests. What other people are doing in their own countries should not form the basis of what the American people do; in fact this is an opportunity to capture American entrepreneurs and have them incorporate in their own country.
Any discussion of the impact of regulation of Bitcoin on other jurisdictions should be made in the context of how America can outperform other countries, and the Trump de-regulation plan not how it should slavishly imitate them and duplicate other countries mistakes.
Step 12
Eliminate the difficulties with digital currencies. Ignore the fictitious impact on financial sanctions.
We are now entering a world where many of the old policy tools will cease to function. Financial sanctions are one of the tools that will need to be abandoned for tools that work. The government cannot expect everything to remain the same forever, including the policy tools it regularly uses today.
Financial sanctions will be made toothless by Bitcoin; I offer the possible future scenario, describing what this might look like:
Russia and America are now working for their mutual interests and both completely embraces Bitcoin. It is now impossible to stop money flowing in and out of all countries. SWIFT has largely been abandoned as the majority of the world moves its money using Bitcoin.
The flow of money cannot be stopped. There are billions of Bitcoin transactions every day. There is no way to keep track of them all, even though each one is absolutely secure and tracked in the publicly viewable Blockchain.
The old tools of financial sanctions, having been abandoned have been replaced by banning orders and other tools that stop the movement of goods and people. Money while it is being transferred is now completely beyond the reach of any government.
New York, being the centre of all Bitcoin business has a unique position of being the leader in software and skills. There has been an unprecedented economic boom in America thanks to Trump, who has decided that interfering in other peopleâs affairs is unprofitable.
As it is in Switzerland, unemployment is a fraction of a percent. Prosperity touches every part of American society. The old concerns about sanctions and tiresome international affairs are now left to the countries that did not embrace Bitcoin and reap the benefit of investment in time and skill that has paid off very well for America.
Sanctions donât matter any more, any more than drug prohibition matters since the global decriminalization and legalization took place.
The date is 2018
This is exactly how the government should be thinking; not about the narrow-window events of today, but of the quickly arriving future, where it should be planning to be âdestination number oneâ for all Blockchain entrepreneurs. The Bitcoin mediated future is going to happen. This is inevitable. The only question is what is Americaâs position going to be in it, once it is in full swing.
Step 13
Ignore the small risks currencies pose to monetary and financial stability these risks are not significant, compared to the benefits.
Bitcoin is not money, it is a means of moving money from A to B. Only the government has the power to levy tax and declare what is legal tender and what is acceptable for the payment of taxes. This means that there will always be a demand for Dollars, no matter what happens.
The Tally Stick (14) is a good example of this, and is in fact a close analogue of Bitcoin. The Tally Stick, an ordinary stick of wood approximately three feet long and an inch square in profile, had a zigzag cut made along its length, creating two unique halves that fit perfectly together. One half was âspentâ out into the economy, the other retained by the Kingâs treasury. This is directly analogous to the public and private keys in modern cryptography, invented by the British, seven hundred years before the advent of the computer (15).
The treasury only accepted pieces of the Tally Stick as payment for taxes. The half of the Tally Stick released into the economy therefore, was extremely valuable, and it was itself split along its length and sold for gold. The Tally Stick is the longest running example of a single form of government money in the world.
Now, in the 21st century, the same ideas that powered the Tally Stick are at the root of the design of Bitcoin; the split keys that power the public key cryptography that secures the Blockchain. The difference today, is that the government, instead of issuing Tally Sticks, issues Dollars, and only accepts Dollars in payment of taxes. It therefore has a very deep and powerful mechanism of control over the economy, and it doesnât matter what people choose to use as money; they must ultimately acquire Dollars to pay taxes.
With that powerful compulsion in place, the Dollarâs value will remain very stable, just as the Tally Stick remained stable and useful for over seven hundred years. The Dollar is not going anywhere, unless the Federal Reserve decides otherwise. There is therefore no risk to financial stability with Bitcoin. The real risk is trying to control Bitcoin, and America losing pole position, with the Bitcoin flowing through, out of and away from the USA.
Conclusion.
The future is going to look very different from today, to the same extent that the pre printing press world looked different to the post printing press world. Banking as we have known it will be a thing of the past; dis-intermediated, peer to peer money transfers will be the norm.
Despite all of this, people will still need somewhere physical to live. They will need services. How these services are paid for and who provides them is the question. It is hard to know what the answer to that question is, but for certain, there will be a transitional period where the previous system is transformed into the new one.
The banks, as storage houses for money are in a prime position to reinvent themselves in the Bitcoin era. They have the infrastructure to service the population and this should not be thrown away on a whim.
If the services described in part here become a reality, and Bitcoin finds a home in another territory, you can be certain that the banks here will still be completely eliminated, with no vestige left behind. Think of the Woolworthâs that used to be a feature of every main street in America, that no longer exist. The same will happen to the main street bank, and the companies that own them, and the New York as a major financial centre, should the locus of global Bitcoin activity settle in another jurisdiction.
Whatever shape the future takes, we want it to take root and flourish in America, and the formula to make that happen is well understood by the Americans who know their history. A 150 year moratorium on the regulation of Bitcoin will achieve this desirable end. There will be a strong temptation to try and control and shape what is beginning to emerge with Bitcoin . You must resist this temptation President Trump, and allow the Bitcoin to flow in America.
The effects that I describe here are already beginning to take hold. As I mentioned earlier, Australia has just learned (16) the hard way that what I am saying is true; CoinJar, an Australian Bitcoin Wallet start-up has just decided to move to London from Melbourne. This is a direct result of the Australian government mischaracterising Bitcoin as money, and forcing the charging of VAT (in Australia, âGSTâ) at a rate of 10% on all purchases of it. In addition, Australian Credit Card holders have been circumventing this tax by going online and registering with the American CoinBase to purchase Bitcoin, completely cutting out Australian business and the Australian government.
Had the Australian government taken a rational hands off approach, CoinJar would never have left Melbourne, Australians would have a local company to deal with, would have shunned CoinBase, and the government would be taxing CoinJarâs profits. Now the Australian government will get nothing, and the Australian consumer continues to use Bitcoin globally oblivious of any irrational local law.
Regulation only works in a space where it is practical to enforce. In Bitcoin, it is impractical to enforce regulation which in any case, is an arrow being shot at an impossibly fast, invisible target, by a blindfolded archer that can only ultimately shoot himself should he hit his target.
The Federal government must now either try to understand and fully grasp the un-knowable future implications of Bitcoin, with the comprehension of a software developer, the insight a technology futurist, a soothsayer with a crystal ball and the intent of an entrepreneur, or it must step back and make an easy leap of faith that software entrepreneurialism is the ultimate engine of progress and prosperity in the 21st century.
Anything less than this will result in America missing the first great technology breakthrough and opportunity of the 21st century, a breakthrough similar in magnitude to the invention of the printing press or the commodity home computer. This breakthrough is the emergence of a world-transforming new technology, shifting all registration and transfers of property, money, things and processes we cannot imagine, to a neutral, infallible, incorruptible, âSilent Automated Guardian of Transactionsâ, the ultimate impartial witness. Bitcoin.

The most important footnote of all. Buy me beer.
1 Examples of large scale sites using online pseudo monies:Cartoon Doll Emporium âCartoon Dollarsâhttp://www.cartoondollemporium.com/prepaidcard-finder.htmlDD Tank âCoinsâhttp://ddtank.game321.com/guides/interface/shop/505.htmlGaia Online âGaia Cashâ http://www.gaiaonline.com/payments
2 Purse.io: https://www.purse.io
3 The ghosts of Skype past: How Estoniaâs biggest tech export is still powering its startup scene today http://www.zdnet.com/the-ghosts-of-skype-past-how-estonias-biggest-tech-export-is-still-powering-its-startup-scene-today-7000026845/
4 What are multi-signature transactions?http://bitcoin.stackexchange.com/questions/3718/what-are-multi-signature-transactions
5 Blockchain â Bitcoin Wallet: https://itunes.apple.com/us/app/blockchain-bitcoin-wallet/id493253309?mt=8
6 Libre Office, which used to be called âOpen Officeâhttp://www.libreoffice.org/
7 Ubuntu Desktop Linux: http://www.ubuntu.com/desktop/take-the-tour
8 The Multibit Bitcoin Client: https://www.multibit.org
9 Missed Alarms and 40 Million Stolen Credit Card Numbers: How Target Blew It: http://www.businessweek.com/articles/2014-03-13/target-missed-alarms-in-epic-hack-of-credit-card-data
10 PlayStation Network hackers access data of 77 million users:http://www.theguardian.com/technology/2011/apr/26/playstation-network-hackers-data
11 OPSWAT Anti-Virus Market Share Report:https://www.opswat.com/about/media/reports/antivirus-january-2014
12 Trezor The Bitcoin Safe: https://www.bitcointrezor.com/
13 Ledger Wallet: https://www.ledgerwallet.com/
14 Split Tally Stick in England:http://en.wikipedia.org/wiki/Tally_stick#Split_tally_in_England
15 Documentary âThe Money Mastersâ: https://www.youtube.com/watch?v=iDtBSiI13fE&feature=youtu.be&t=18m36s
16 CoinJar Relocate From Australia To UK, No Longer Charging GSThttp://qntra.net/2014/12/coinjar-relocate-from-australia-to-uk-no-longer-charging-gst/
Mining
By Paul Sztorc
Posted January 29, 2017
In our future world of Payment Channels, there is really no way that even a 100% pool can attack users. We will always need to be ready to change Bitcoinâs PoW algorithm.
This is a written elaboration of this video from last summer.
Motivation
New Knowledge
Previously, I argued that the concept of âminer centralizationâ is unhelpful (and possibly meaningless).
With this post, Iâm going to try to provide something that I think is more useful. In other words, the previous post attempted to destruct an idea of âminer centralizationâ, this post attempts to construct something useful (on the same topic).
Sidechain Criticism
Secondly, there are some people who complain about my sidechains work (not to my face of course, only in whispers to their already-friends). After slowly and steadfastly eliminating all possible realms of concern, category by category, I presented an extreme view at Scaling Milan, in the presence of many of Bitcoinâs brightest. I was then able to flush out any remaining criticisms, which were all about mining.
âEffectively Centralizedâ
I have a third distinct goal â to demonstrate that âBitcoin worksâ.
Most of Bitcoin âjust worksâ already, as is obvious. Signatures work, hash functions work, the data is displayed to the user, transactions are processed, et cetera.
However, âminingâ canât easily be shown to âworkâ.
I believe that this is due to the âslowâ life-cycle of mining. For digital signatures, the life-cycle (generating the keys, signing a transaction, checking the signature) is âfastâ. We can perform the experiment many times. Each time, the signature works as advertised. Same goes for hash functions, database calls, CPU usage, the font, et cetera. These subsystems can all be tested a hundred times, and the results will always generalize to the future (because nothing about them changes over time). Mining, however, is constantly changing. We can not demonstrate that it will work in the future, merely because it works today.
It is true that âdevelopmentâ is in the same boat. However, any audience familiar with [1] open source, [2] soft forks, and [3] this intuitive upgrade strategy, will probably be immune to nagging of this kind. Plus, the software has already been writtenâŠso what are you complaining about? That someone, somewhere, could at some future point write some evil software and trick you into installing it? Welcome to the internet?
So âminingâ is where the criticism lands (excluding goal-related criticism, such as the fixed money supply). And this criticism fuels interest in proof-of-stake and other mining âalternativesâ.
My point of view is that this criticism is unfounded. When it comes from the ignorant, we can simply ignore it. However, it comes also, on occasion, from our most senior core developers. My opinion is that, at best, this is overzealous paranoia on their part, as they are unduly distressed over something which is out of their control. At worse it represents a childish need to be noticed and recognized as an authority or expert â a kind of subconscious racketeering.
Mining Threat Model
What can miners do to attack users?
Threat models are important. Dr. Back linked to this thread by Mike Hearn, cited it as a âuseful threadâ and reproduced it in full on the bitcoin-dev mailing list so that it âmay reach a wider audienceâ.
Excerpt: âEstablishing a threat model is an important part of any security engineering project. In the early days of secure computing, âŠusability, performance âŠwere sacrificed to try and defend against absurd or very unlikely threats just because someone identified one âŠthe resulting product sucked and nobody used it, thus protecting people from no threats at all âŠPGP is a good example of this problem.â
I would like to apply the âthreat modelâ concept to Bitcoin mining specifically, instead of Bitcoin as a whole. While Bitcoin tends to be many things to many people, mining is an area where there is wide agreement over what should be accomplished: miners should [1] include transactions in blocks (only excluding them if they are invalid or if they pay a sufficient fee/kb), [2] pursue their long-term self-interest in a docile and transparent way (ie, âno surprisesâ), [3] compete honestly (ie, on merit), and [4] maintain their own existence (so that the Bitcoin network doesnât stall out).
The threat model will consider two classes of miner behavior:
Class I: What miners are capable of doing. Class II: What miners are motivated to do.
( Motivation is a reliable force â the laws of incentive are comparable, in strength, to the laws of physics. Just look at any highway, and youâll see that the cars are snapped into their lanes, as if the thin lines of white paint were walls of concrete a mile high. )
0. Nodes and Miners
The validation of blocks is the networkâs top priority, and should concern all Bitcoiners. However, the mining of blocks is none of the networkâs business, and should concern no Bitcoiners.
The threat model is independent of full node costs (ie, decentralization). Specifically, the model assumes that every user is running a node (or else, each user is able to start one up). That certainly may not be the case, but those variations belong to a different threat model and a different day. This model defines âthe networkâ as whoever is running a full node, and works from there.
Are They Really Separable?
Let me clarify my view on the connection between [1] an ASIC chip (ie, âthe thing that minesâ) and [2] the software which administrates this chip (ie, the software that determines âwhat is minedâ). Many believe that each miner must run a full node, else something terrible will happen. But I think that this belief cannot be correct.
The security model for Bitcoin is, unambiguously, that users run full nodes in order to validate payments. The full node of User A, protects him against the fraudulent activity of Users B through Z (including the fraudulent activities of miners âMâ and âNâ). Because of Aâs full node, A is robust to any mistakes made by B-Z.
Then, the requirement that miners run full nodes is at best redundant. A is already immune to any mistakes made by M and N. So there is no inherent requirement that a node be present to supervise an ASICâs activities.
Quite the reverseâŠ
Capitalism and Efficiency
Since no node-requirement exists, it is really none of Aâs business what software Miner M and Miner N choose to run (or, chose not to run).
For example, here is an article on ASIC-design from last year, about âApproximate Hardwareâ, stating âa processor that needs to guarantee correct operation 100 percent of the time sometimes consumes almost two times more power than a processor youâre asking to be correct only 99 percent of the timeâ. The article concluded that new designs could increase mining ROI by a staggering 30%, by allowing for some occasional miscalculations.
Regular users are entirely unaware of these miscalculations, and are completely unaffected by them.
In fact, regular users can never be affected by a minerâs miscalculations. Every thing a miner does is âhard to generate, easy to verifyâ. The merkle tree, the construction of the header, the checking of the headerâs hash, and the verification that the hash value meets the difficulty requirement. They are all near-instantaneous.
The only slow operation is the validation of each transaction (specifically, signature-checking), but miners have no reason to use âapproximateâ computation here â they cannot speed the process up, because it is limited by the arrival of new valid txns from users. Secondly, these computations have nothing to do with the headerâs proof-of-work and so there is no performance incentive.
Improvements in Pre-consensus Can Maximize the Modularity of PoW
In addition, it is my belief that, in the future, Bitcoin may have [1] better propagation technology, and [2] a more âpatientâ demand landscape. As a result, there will be no uncertainty whatsoever about a blockâs contents. For example, by the time block â35â is found, the network will already know, not just the transactions of 35, but also the transactions of block 36. In fact, the network will know exactly which txns will be in blocks 37, 38, and 39. Any ambiguities (including any mistakes, bluffs, attacks, feints) will be occurring far in the networkâs future, and will be resolved before the header gets any attention from the ASICs. Therefore, âmiscalculationsâ will be unable to intersect with the double-sha256 computation that we today refer to as âminingâ.
But let us return to the present level of technology.
Miners Will Never Voluntarily Mine an Invalid Block
In all cases, miners get to choose what they mine. The mining-process may be imperfect, or inherently uncertain, but the miner can choose what goes in to the mining-process. They can either put an InvalidBlock âinâ, or put a ValidBlock âinâ. While a lazy miner may choose not to learn whether his block is a ValidBlock or an InvalidBlock, they are equally heavy, when it comes to hauling them over to the mining machine and dropping them in.
The mining process itself is costly, and this cost is also independent of the Valid-ness of the block. Therefore, if a miner inserts an invalid block, and solves the block, then this is, in fact, immediately costly to the miner! He has, in principle incurred an opportunity cost, as if the block were valid he could collect BTC from it.
An invalid block is costly right off the bat. Therefore, if âinvalid miningâ is ever to be incentive-compatible, an attacking miner will have to find a user for the InvalidBlock. The attack must have a marginal revenue which is greater than its marginal cost (this cost being equal to the value of each block).
What might an invalid block be useful for?
At best, the block can be used to temporarily distract or confuse some network participants. If our attacker has 51% of the hashrate, it will take him (on average) ~20 minutes to find another block. Whatever his intentions (to build atop the invalid block, or on top of its [valid] parent while other are distracted), it is inconceivable that the distraction could last long enough for anything significant to happen.
Hard to Generate, Easy to Verify Perhaps we can combine the previous two sections to imagine a worst-case scenario where a miner has an incentive to accidentally mine invalid blocks, and then broadcast them. Instead of requiring less power, a worst-case âapproximate minerâ could work ~twice as fast but have ~49% false positives. These âalmost correctâ false-positive blocks would meet the proof of work requirement, but be invalid. Once a miner finds th Putting on a very large âconspiracy hatâ, we might then assume that miners could deliberately construct an invalid block and then use this software, hoping that it Since they meet the proof of work requirement, nodes would have to check the blockâs contents for accuracy, which would be costly. Theoretically, this would be a misaligned incentive, because individual miners would find this profitable, but they could collectively be jamming the network (or, each other) with hard-to-verify blocks. This cannot be a concern of ours because of the way blocks are computed. The stage where transactions are assembled into a Merkle tree is already fast, and there is very little to be gained by making it faster. The stage where a blockâs header is hashed repeatedly to find a winning nonce (and thus mine the block), is the stage where speed is desired. Since the node software is not running on âapproximate hardwareâ, it will check this second stage without errors. As everyone who is familiar with Bitcoin knows, this second stage is merely one double-sha256 computation of an 80-byte header. However, in do so, the miner incurs an opportunity cost. This scenario requires us to assume that miners are malicious. Even in this worst-case scenario, the miner would need to be deliberately inserting invalid data into blocks. This is because there is no need to âspeed upâ After all, âthe computationâ is a series of SHA hashes (to roll up the block into a Merkle tree), and then finally ~nah, it is fine because they wouldnât garbage in. On top of that, we assume that the miner is willfully malicious, and deliberately inserts invalid data into blocks .. Solved with my preconsensus. ~~~ This would strip nodes of much of their DoS protection, and they would need to wait for many confirmations. For a user who waits for 6 confirmations this does nothing at all, becauseâŠâŠ This would be no different from any other DoS attack, and A would respond in the usual way, by refusing connections from peers who give him bad blocks. Moreover, Satoshiâs design fights back the tide of DoS, by requiring users to wait ~6 confirmation
In Praise of Node-less Miners
Ultimately, the simple truth is this: the miner is paid if he finds a valid block. How he finds this block, is his business. (How we validate it, is our business.) If a miner chooses to take a riskier, luck-based approach, then he bears the costs and benefits of that decision, just as he would if he cut corners on cooling equipment, or if he hired cheaper-but-less-reputable employees.
In my opinion, this principle applies equally to all âvalidation costsâ. Miners can minimize these costs in any way they deem appropriate. And this is exactly what they do, every day. Many developers today complain about SPV validation, but it is in principle no different from âApproximate Hardwareâ â it is an efficient way of finding a valid block. The fact that it sometimes might find an invalid block, is the minerâs problem, not ours. Miners are the ones who stand to lose their mining-revenues if their blocks turn out to be invalid.
In fact, full-node-hardliners such as Peter Todd should praise the broadcasting of invalid blocks, not condemn it, as the presence of invalid blocks (and -really- nothing else) is precisely what incentivizes users to run full nodes in the first place. Here is a bitcoin-dev email where PT espouses precisely this view (that the blockchain should contain some invalid data, such that users are forced to check the validity for themselves).
Implications of âSegregated ASICsâ
The most direct implication is that the ASIC equipment can be hidden. The mining-critical information is on the order of bytes, and it can therefore be snaked around the internet through TOR and VPNs before arriving at the actual ASIC chip, Once a block is found, its header can also take a brief secrecy tour before being revealed to the world.
This will be explored further in the equilibrium analysis which follows the threat model. Because the two are connected, it is occasionally necessary to introduce a concept in one section and justify it in the other.
Scope of this Essay
In conclusion, this post is about a miner threat model which is not a node threat model.
Many, including Dr. Back, have claimed that it is bad if nodes are burdensome to run. With expensive nodes, users have only expensive recourse if these nodes come under pressure from violence-monopolies (such as governments or mafias). In this scenario, Bitcoin loses its distinctive âpeer to peerâ property, as someone is now a privileged non-peer.
Dr. Backâs concern is a perfect example of something which is not in the miner threat model, because it is fully dependent on node costs. This model is independent of node costs. The threats I describe in this post will apply, whether nodes are expensive or cheap. And they will continue to apply if node-costs increase or decrease.
1. Setup
Let us consider a worst-case scenario, where:
- There is a single mining pool.
- Russian/Chinese Govât / Evil Corporations / Mafia / NSA / etc are watching the Uni-Pool carefully.
- Miners trust the Pool to manage the blockchain, and run minimal software (âcivilianâ full nodes), to make sure that they are getting paid for their Hashing work.
However, I will assume that the physical equipment is hidden, and that there are no disparities in ASIC chip-efficiency.
These assumptions result from the equilibrium analysis, which follows this section.
2. The Adversaryâs Abilities
First we will look at what miners âcanâ do (Class I) to users.
A mining pool has, by my count, only two malicious powers:
- Re-Write (â51% Attackâ) â directing Hashers to conduct a huge rewrite of the chain.
- Non-Write (âCensorshipâ) â preventing data from getting into the blockchain.
3. Cost of Attack
Each attack is costly â it impoverishes the miners, forcing them to pay an opportunity cost equal to their forgone transaction fees. Obviously, for the Non-Write attacks, each forsaken txn has fees which could have been paid to miners. For the Re-Write attacks, notice that the uni-pool earns tx-fees for each new block it mines, but none for any old blocks. If the uni-pool orphans itself, it will have mined two blocks but collected fees only once (if it instead mined two new blocks, it would have collected fees twice).
( This assumes that each block will be constructed to maximize total fees, for which I have argued in the past. )
4. Baseline (No Attack-Benefits)
If attacking has no benefits, the uni-pool never has a motivation to attack. This is a complete victory, for everything of Class II.
On top of that, it is also a complete victory for all of Class I, if both of the following are true:
- Anyone can create a new pool.
- Miners will all always switch to whichever pool maximizes their revenue.
If these conditions are met, the pool is simply unable to get away with any non-revenue-maximizing activities.
And both seem quite achievable. The first condition can be met with some open-source pool management software. The second is more complex â the biggest challenge would be the collective action problem inherent to coordinating the switch to the new pool. We can further break this step into three: [1] recognize that malfeasance is taking place, [2] choose a new pool, [3] choose a time to switch.
Of these sub-requirements, the second and third are trivial. Even the first sub-requirement is very solvable. For Re-Write problems (ie, a large chain reorganization), there is no ambiguity whatsoever â this misbehavior will be noticed, by everyone. Miners will not be happy about orphaning themselves, and will have a reasons to switch pools. For Non-Write (âcensorshipâ) problems, the victims can prove that they are under attack. For example, full nodes might collect âsuspicious transactionsâ (which should have been mined but mysteriously arenât), and as these pile up, it will become obvious that something is clearly amiss (and that there is money to be made by ditching the uni-pool for a new one).
5. Benefits to an Attacking Miner
The previous section assumed that the miner didnât benefit from the attack.
Of course, that isnât true. Certainly, with Re-Write attacks, the attack can unspend all of the money he has recently spent, and purchase things without paying for them. This threat was highlighted by Satoshi in his whitepaper:

âŠand we will discuss it two sections from now.
For the Non-Write attacks, we can further divide into three flavors:
2a. Freeze Funds â barring a specific txn (or class of txns) from entering the chain. 2b. Denial of Service â barring all txns from the chain (this puts the Bitcoin network âon strikeâ). 2c. LN Corruption â denying justice to a user who is being robbed by a LN-counterparty.
An attacker might benefit from 2c by conspiring with the robber. An attacker cannot directly benefit from 2a or 2b, outside of a desire to cause mayhem. In a future world of Schnorr signatures, 2a will likely be outright impossible.
6. Coercing the Miners
It is true that an adversary may pressure the uni-pool to block transactions, or apply policy to them arbitrarily. For example, the adversary may wish to âfreezeâ an individualâs account, holding it hostage such that he cannot spend money until he meets some arbitrary criteria. Criminals may simply hold an account ransom, such that no money can be spent until the victim agrees to pay some bribe.
As Iâve previously argued, this is unlikely to work against the pool, because the pools will compete strongly on efficiency, and censorship is inherently inefficient (as it leaves transaction fees on the table).
An adversary may put pressure on the ASIC chips themselves. I describe why this is infeasible in two later sections: the âequilibrium analysisâ, and âevolving to extinctionâ. But for now I will simply remark that, if someone can coerce an ASIC-owner to force the ASICs to behave a certain way, then, as far as Iâm concerned, the ASIC chips have already been stolen. The âcoercerâ is the de facto owner of the ASIC equipment (not whoever originally paid for it). Then, the ASIC-owner (whoever that may be) may want to do something to us, that we donât like. I think that they can only do four things:
- Harass individual Bitcoiners by censoring their payments.
- Mine empty blocks, to cause mayhem.
- Steal payments from a LN channel by allowing a counterparty to broadcast a previously-invalidated transaction state.
- Steal payments by rewriting the chain.
7. Our Best Responses
What can we do, if we are attacked in any of these four ways?
- Increase transaction privacy.
- Use payment channels.
- Use âhealthyâ channels (rebalance to avoid one-sidedness, long custodial periods).
- Change the proof-of-work algorithm.
The first two are quite straightforward. Privacy protects individual users from being targeted, and payment channels -once open- allow users to transact without minerâs knowledge or permission.
This emphasis on channels exacerbates the threat of channel-theft.
However, users can discourage channel-theft by making it expensive. Like all censorship, the cost to the miner is the foregone tx-fees, and users can cheaply amplify channel tx-fees. This is because lightning-channels are designed such that, if your counterparty attempts to defraud you, you [1] get some of your money back immediately, and [2] can immediately broadcast a txn claiming all of your counterpartyâs money.
Therefore, the strategy is simple: always require your counterparty to have lots of their money in the channel. A channel might start 50%-50% or 60%-40%, but as it gets nearer to 90%-10% or 95%-5%, users should rebalance the channel to keep it as close to 50%-50% as they can. This allows the victim to use the attackerâs money to pay a large transaction fee (more than the attacker could possibly steal from the victim, and more than the attacker could offer to a conspiring miner).
For example, imagine a channel starts (you: 50 BTC, they: 50 BTC), and progresses to (25, 75), and then (90, 10). Imagine then that an attacker attempts to defraud you by broadcasting the (25, 75) state. You immediately get 25 BTC of your own money, and you can also get 75 BTC if you can broadcast a single transaction within the next 1000 blocks. Since the transaction is worth 75 to you if broadcast, and zero otherwise, you (or someone else) will pay a tx fee of up to 75 BTC to get this transaction included in a block. You can therefore outbid your attacker, who is only earning 65 from this maneuver. In contrast, if youâd allowed the state to drift through (100,0) before reaching (25,75), then the attacker would have nothing to lose by broadcasting (100,0). Therefore, you should not allow this.
Secondly, you can insist on a long custodial period. Channel-theft requires a miner to retain total censorship-dominance for many consecutive blocks. If we are not in a uni-pool situation, this all-but-guarantees that channel theft will fail immediately (on the grounds that it will almost certainly fail eventually, and that whichever miner who causes it to fail first will get more money). Even in a uni-pool situation, a long custodial period can help tremendously (on the grounds that a victim merely needs to outlast the replacement of this inefficient pool).
I will deal with the PoW-algo change in the final section of this essay âevolving to extinctionâ.
8. Conclusion
In the above sections, I have assumed that all of the miners were joined together in a single pool. Even with this assumption in place, I have searched for ways in which users can realistically damage users, and not found any.
And this theoretical result mirrors reality, as there have been no instances of any of the four attacks (censorship, miner strike, channel theft, or 6+ block rewrite). Miners have historically stolen some money, but these instances support rather than refute my analysis, as they are all instances of miners aggressively maximizing their revenueâŠwhile playing entirely by the rules of Satoshiâs protocol.
However, a new question remains: will things always be as safe as they are today?
To answer that, we will need to guess at what mining will be like once everything stops improving and changing. If mining is OK today, and mining is also OK in the far future, then we might conjecture that a line connecting the two points will only travel through âOKâ territory.
Miner Equilibrium Analysis
What will mining look like in the future? Where is it going?
First, Iâll separate âminingâ into 4 sub-processes:
- Hashing â the rapid, industrial-scale calculation of 2x-sha256 hashes.
- Logistics â the shipping of information from users, to miners, and back to users.
- Exchange â selling new BTC in order to reimburse mining costs.
- Income Smoothing â reducing the uncertainty in revenue arrival-time.
Today, the âmining poolsâ perform most of sub-process #2, and all of sub-process #4. ASICs chips perform sub-process #1, and individual miners perform #3.
Letâs get exchange out of the way, because it is quite simple.
1. (#3) Exchange
Miners certainly compete on their ability to âmake the mostâ of their newly-minted BTC.
For example, some miners glean extra value from Chinese capital controls, by using their Chinese currency (which is trapped in China) to purchase power, in order to mine BTC which they later take out of the country to sell for other international currencies.
It is also known that some buyers will pay a premium for large, private, over-the-counter purchases. Miners often facilitate these transactions, using their newly-minted BTC.
Miners will continue to use these and other strategies. Some, such as the first, may encourage power to be sourced from a certain jurisdiction or purchased with a certain currency. Others, such as the second, merely encourage miners to practice another skill (or diversify further, into intermediaries).
2. (#1) Hashing
ASIC designing is a quest for efficiency â turning dollars into hashes as cheaply as possible.
Eventually, technological knowledge -of all kinds- will saturate. Everyone will know the best techniques for building chips, for cooling the chips, the cheapest sources of power and so forth.
Since very much has been said about this already, my only contribution here will be to agree that hashing will be co-located with cheap sources of power, and that these cheap sources of power will be geographically distributed.
This is largely for physics reasons: the transportation of energy is not free, and there are certain terrain features which are conducive to the production of energy (geothermal, hydroelectric, solar). As a result, âHashingâ will probably eventually consist of many chips, all of uniform quality, co-located with cheap sources of electrical power.
It happens to be the case that ASICs produce waste heat, and heat radiates in all directions. If we imagine a cube of ASICs, 3x3x3, then the 8 ASICs on the corners of the cube will cool fastest, followed by the 12 which surround each âfaceâ of the cube (where the dots are, on a pair of dice), followed by the 6 in the center of each face, with the single remaining center-ASIC being cooked like an oven. This effect diminishes if the ASICs are physically separated from each other. While it is often fashionable to point this out, the effect operates on very small scales (a few meters), and is unlikely to affect the risk of confiscation.
3. (#2) Logistics, ie âInfo-Shippingâ
Logistics is quite a puzzle. Iâm not sure Iâve completely solved it, but I will share with you my results so far.
In order to mine, a miner needs two pieces of information that he cannot himself create:
- hashPrevBlock â the hash of the blockheader corresponding to the block which [1] is valid and [2] is at the end of the heaviest-work chain of blocks.
- hashMerkleRoot â the hash of a set of transactions which are [1] valid and [2] pay appropriate tx-fees.
Since miners both buy and sell this information, to other miners, we are in a highly strategic environment which I will refer to as Broadcast Strategy.
A naive miner would: connect to the network, download and validate all blocks, download and validate all transactions, search for a block, and then, if a block is found, broadcast the block immediately to the network.
However, over Bitcoinâs eight years, the broadcast strategies have grown to be increasingly sophisticated. Currently:
- Hashers outsource their validation work to pool operators.
- Pool operators frequently take risks, by:
- âŠassuming PoW-sufficient blocks are also valid-blocks, and switching to them immediately.
- âŠassuming certain transactions wonât be double-spends, because they are too undesireable (and including them before checking the prevBlock).
- Pool operators also connect to rival pool-operators, to âspyâ on them and avoid falling behind.
In fact, no one knows for sure exactly how the miners ship their information back and forth. There was once a single mempool that was shared by ~75% of the network hashrate. Perhaps there still is.
Letâs talk about two of the most important Broadcast Strategies. These are instances in which you do not broadcast immediately, in what was originally called âBlock Withholdingâ.
Block Withholding Attack
However, the current âblock withholding attackâ is named after the phenomenon that is is in fact directly profitable to do something a little bizarre: join a mining pool, work for it honestly, submit the losing blocks, but then sabotage the pool by not relaying any winning blocks. The bigger the pool, the greater your disproportionate profits.
And, most interestingly of all, you can attack all open pools, and itâs just as wonderful for you as if you had attacked a single gigantic pool.
Perhaps we should rename it to the âpool withholding attackâ, as it only works on pools.
In fact, it only works on open pools (pools where anyone can join). And, if you join a âclosed poolâ, it is unclear to me who actually âownsâ or âcontrolsâ the ASIC hardware â it seems that the closed-pool operator is a partial owner of some kind. Obviously, a solo miner can be said to be running a closed pool, consisting of only himself as the sole member.
So, joining an âopen poolâ is costly, relative to joining a âclosed poolâ, or âsolo miningâ (ie, mining without a pool, which could itself be considered as a closed pool with just one member).
Is it worth it? Clearly, most of todayâs mining is done in open pools. What are the benefits of todayâs open pools?
- Convenience (ie, âspecializationâ) â Hashers can just focus on hashing, and point their hashpower to some destination.
- Income Smoothing â Hashers can be certain to avoid long periods of zero revenue.
- Collective Barganing â Hashers can pledge themselves to act as a group, giving their leader (the pool operator) more negotiating leverage.
My guess is that, in equilibrium, none of these three advantages will remain, let alone be attractive enough to outweigh the costs of the PBW-attack.
Peter Todd proposed that we fix the attack, which unfortunately requires a hard fork.
If the attack is not fixed (as I expect it wonât be), then we will probably see a decline and disappearance of open mining pools.
Selfish Mining
On the opposite of the naive âbroadcast immediatelyâ strategy, would be an aggressive ânever broadcastâ strategy. By not broadcasting, you deny other miners the ability to build on your blocks. This was originally referred to as a 51% attack, as the attack -so we thought- would only be effective if a miner had at least 51% of the hashrate.
However, it was noticed that one could refine the ânever broadcastâ strategy, specifically to take advantage of those miners who were using the naive âbroadcast immediatelyâ strategy. If the agent has sufficient hashpower (about 30%), then he can reliably âjukeâ the âbroadcast immediatelyâ miners, and accumulate enough statistical luck to eventually claim 100% of the block rewards.
This strategy came to be known as âSelfish Miningâ after a paper by Emin Gun Sirer and Ittay Eyal with that phrase.
The implication of Selfish Mining, is that the strategy=âbroadcast immediatelyâ is vulnerable to invasion by strategy=âselfish miningâ.
However, a peculiarity of the SM is that it is itself horrifically unstable if a large % of hashpower uses it. For example, if 100% of the network uses it, no one will ever see any blocks at all, as no miners will be publishing any. If three groups of 33% hashrate use it, no blocks will be seen until the remaining 1% âbroadcast immediatelyâ miner finds a single block and publishes it. Then the network will explode forward as each of the three publishes their private chains. If two groups of 50% use SM, then not only does the network cease to exist (as no blocks are ever being published), but even if it could magically exist (say, blocks are magically and simultaneously published as soon as each of the two groups has 5 private blocks), then âselfish miningâ would actually be worse than âbrodcast immediatelyâ. This is because there is no one for selfish mining to exploit (the profitability is the same, under both strategies); the revenue-variance, however, is much higher.
So, âselfish miningâ is good if many rivals are using âbroadcast immediatelyâ, but it is bad if many rivals are using âselfish miningâ.
There is no known way to discourage selfish mining, other than to force >70% of the hashrate to decline to use the strategy.
Now letâs talk about a way to force someone to broadcast to you.
âSPYâ Mining
The technique of spy mining is one where pool operators connect to rival pools to âspyâ on what theyâre up to. If you âspyâ, then it effectively forces everyone you spy against to use the âbroadcast immediatelyâ strategy, at least to you.
This is done by waiting for the rival pool to command its ASICs to work on a new block header. Then, you just re-route that header to all of your own ASICs.
If all pools are open, then spy mining is a dominant strategy. The intuition is that you can choose to ignore the âspiedâ information, if you need to.
( Incidentally, the only time you would choose to ignore this information is if you âspiedâ that a rival found a âproblematic blockâ. A âproblematic blockâ would be one that was unlikely to make it into the final chain, perhaps because it is very large and rivals are not spy-mining. Usually, you have a pure advantage if you spy-mine. If others are spy-mining, you are at a disadvantage if you donât spy. )
Not only is spying dominant, but it is probably also dominant to immediately mine on whatever header your rival pool is giving everyone. There may be complex strategies that pools use to smoke out spies, but they probably wonât work, as the information is only flowing âone wayâ (from rival-pool to pool to ASIC) for the duration of the block search process (~10 minutes). Since attempts to âsmoke out spiesâ are costly to the rival pool operator (in wasted hashrate), and since they ultimately achieve nothing, it is probably safe to assume that any hashPrevBlock that the rival-pool-operator sends is genuine.
Of course, to prevent yourself (and everyone) from joining an invalid chain, you should also validate the block as quickly as possible. If you are unable to validate the block (within, say, 10 minutes), you should reject it.
Spy-mining is very difficult to prevent. The only known way to prevent this strategy is to close the pool completely â ie, it only contains ASICs that you own (or that are owned by your perfectly-trusted group). Even then, it is conceivable that pools might simply bribe each other for on-demand access to the latest prevBlockHash.
4. (#4) Income Smoothing
When miners are asked âWhy do you use a pool?â they all emphasize âincome smoothingâ above all.
The prospect of going an unlucky week (or so) without any revenue coming in, is one that is extremely distressing to miners.
Interestingly, this concern is purely financial in nature. And the realm of theoretical finance does not even allow this to be a legitimate concern: because there is a perfect -1.0 correlation among miner block-finding, this would all be considered âdiversifiable riskâ. Miners would be advised to buy stock in each other, if they wanted to hedge against this risk.
Of course, miners canât usually buy stock in each other! And not every miner is a corporation! And we donât always know whom to buy stock in!
Nonetheless, it is interesting. I have started working on a âsmart contractâ version of âminer insuranceâ which I think might allow miners to hedge their risk by betting that they themselves will not find a block. Itâs pretty complicated to work out.
Synthesis
Firstly, it is a straightforward application of the efficient markets hypothesis that miners will eventually be earning the lowest ROI possible, and paying themselves subsistence wages. (However, this is true for all industries, and the critical word is âeventuallyâ.)
Secondly, we know that hashing equipment will likely be co-located with cheap sources of electrical power.
We also know that spy-mining is hard to prevent. If unprevented, everyone will use the (very tame and desirable) âbroadcast immediatelyâ strategy.
However, spy-mining requires open pools, which makes it vulnerable to block withholding. Perhaps the block-withholding attack will be fixed, or perhaps pools will become closed (but will still broadcast quickly). Or perhaps pools will have a fee structure that heavily discourages withholding.
We do not see any selfish mining in todayâs mining network. I feel that miners have actively chosen to avoid SM, as it leads to a road of tremendous headache for no net gain.
For example, if one user will [1] single-handedly purchases >30% of the hashrate, [2] closes his pool to prevent spy-mining, and [3] aggressively selfish mines until he is the only pool, he will lead the chain for a time. However, rival miners can guard against this by forming a closed pool of ~70% of the hashrate, and doing selfish-mining of their own.
Nonetheless, since there is a significant risk of uni-poolness, the threat analysis must contain that assumption.
( Which is how the analysis began, if you remember. )
Letâs talk a little more about extreme situations where one agent controls all of the hashpower.
Government permits to mine. â long run, no one will be able to afford these. Peter Todd works for BTCC â https://petertodd.org/2016/block-publication-incentives-for-miners ⊠#### Good News Fortunately, even though these conditions cannot be changed, they are actually relatively favorable to the defensive team. Firstly, there is the basic principle of heat diffusion. This is kind of an âanti fixed costâ, in that it is the opposite of reusable. Imagine that we have two groups of 27 ASICs. Group A has 27 ASICs, each in a different home or office. Group B has 27 ASICs arranged in a cube, 3x3x3. All of the ASICs are initially at room temperature. When they are activated, they will begin to produce waste heat. Group A will be slower to overheat than Group B, because Aâs ASICs can mix with the atmosphere in a full 360 degree radius. Bâs ASICs have problems â the four corner-ASICs have the easiest time, followed by the perimeter non-corners; the six ASICs in the center of each of the outer squares (if the cube were a large die) have it quite bad and the single ASIC in the center is being cooked like an oven. While the pizzeria could recapture the waste heat and use it for more pizzas, now the ASICs are giving off waste heat that warms nearby ASICs. This favors the ASICs being spread apart. Or else, it favors investment in cooling systems to compensate for this. Secondly, ~ âreusingâ the atmospheric temperature. ~ would it be different if the government had to actually build the ASIC hardware.
Evolving to Extinction
Why we need the âchange the proof of work algorithmâ card, and why weâre always going to need it.
The title of this section is based on Yudkowskyâs essay of the same name. In my opinion, EtE is one of the most important pieces of writing on the internet.
In applying it to Bitcoin, my observation is this: there is an entire category of problem which, in my view, cannot be solved algorithmically.
The Problem: Specialization Leads to Fragility
Bitcoin is vulnerable in the following way:
- The world might be âBitcoin Friendlyâ or it might be âBitcoin Hostileâ. To a Bitcoin miner, these worlds are quite different.
- Since more configurations are possible in the âBitcoin Friendlyâ world, the optimal mining configuration of that world will be more âefficientâ than the optimal mining configuration of the Hostile world.
- If the world is Friendly for a time, mining will optimize and specialize for Friendly-world.
- After mining is specialized for Friendly, it will be reliant on the world remaining Friendly.
- Anyone with the power to âchange the world from Friendly to Hostileâ, can probably seize control of all of the Bitcoin Hashpower.
In short, specialization is more efficient, but assumes a given set of parameters. If those parameters change infrequently, we will have extinction events. If an adversary controls the parameters, they can set them one way, leave them that way for a while, and then change them later. This forces the extinction event.
There is nothing we can do to change this aspect of reality. It is a consequence of the fact that the miner-elimination process lacks sophistication. The elimination process is not âintelligentâ enough to comprehend, measure, or respond to the âE2E riskâ. If it were, Step 3 (above) would optimize for the possibility of the world becoming Hostile. Instead, it just counts some numbers and divides them.
The Solution Must Involve Human Judgment
However, we can change how we respond to this aspect of reality. We, since we possess thinking brains, can use our sophisticated brains to comprehend, measure, and respond to the E2E risk.
The challenge is: what response could we make, that would be [1] strong enough to solve the problem, [2] simple enough to have minimal unforeseen consequences, [3] principled enough to be uncontroversial, and -above all- [4] inherently connected to this problem exclusively, such that a scattered crowd of leaderless Bitcoiners, seeking common knowledge and leaderless coordination, would view the response as âwhat other people are most likely to conclude that we will conclude that we should respond withâ.
The problem is one where an adversary comes into sudden possession of the mining equipment. The solution, then, must be one which deprives the adversary of the mining equipment. It also must be some kind of temporary alternative to proof-of-work consensus, by definition, because in this attack scenario, the attacker controls the âworkâ. (This is in direct contradiction to Satoshiâs qualifier âAs long as a majority of CPU power is controlled by nodes that are not cooperating to attack the networkâ.)
The clear solution is to change the proof of work algorithm, and to warn users to âwait for many confirmations until the algorithm-change process is completeâ.
This [1] solves the problem, [2] is simple enough that users can understand exactly what change was made and how it will affect them, and [4] very tightly connected to the original problem. It is a âtemporary alternative to PoWâ for merely the briefest instant, rejecting PoW one time and then renewing our loyalty to it.
To satisfy requirement [3], it must be the case that we only undertake this action if there is a clear need. In other words, if someone attempts a large Re-Write of the chain (and seems to be succeeding).
To protect against channel-theft, I recommend setting the channelâs custodial period as long as possible.
Off-Path Reasoning and Equilibrium
Although our defense cannot be algorithmic, we can modify our behavior so that it includes some of the beneficial aspects of algorithms, namely âtransparencyâ, âpredictabilityâ, and âclarityâ.
Firstly, to avoid mis-coordination, we could have a previously-defined sequential list of PoW algorithms, and this list could even ship with the latest version of Bitcoin Core. Then the required user-action would be as informationally-simple as possible: either press âthe buttonâ, or donât. Pressing the button would move the user to the next PoW algorithm in the sequence.
Imagine a world where all of Bitcoin land could magically commit to behaving such that the phenomenon âa 20+ block Re-Write of the chainâ would necessarily be met with the response âwe all press the buttonâ.
What effect would this have on todayâs adversaries? What effect would it have on todayâs miners?
Making Miners Responsible for their own Problems
Obviously, the miners would want to avoid this doomsday scenario more than anyone. I think it possible that, despite a collective-action problem, some miners might react to physical mining concentration by hiding their own equipment and making light investment in âhidden mining facilitiesâ. These would be relatively inefficient but could be ramped-up on short notice. The purpose of this would be to wait for an adversary to steal (a rivalâs) ASIC equipment, and then to react by this by turning on additional equipment while the adversary is attempting a Re-Write (after all, a two week reorganization will take about four weeks to complete, if an adversary has 51% of the hashrate, and 2.7 weeks if the adversary has 75%). These âsavior minersâ would then [1] save the Bitcoin network from the attack, [2] save their investment from failing immediately, and [3] disable much of their competition (at least, for the duration of the attack).
Making Confiscation Attacks Futile
Most important of all is the effect this would have on the adversaries themselves. Since the attack ultimately canât succeed, there is less reason to attempt the attack in the first place. Instead of âmafia takes control of Bitcoinâ, the newspaper headline would read âmafia vaguely slows down Bitcoin payments temporarilyâ. If we replace the âmafiaâ with the âRussian or Chinese governmentâ, the headline changes from âChina moves to block Bitcoin payments, impose capital controlsâ to âChinese government seizes control of Bitcoin equipment, now worthlessâ. Whereas the former is a victory over the Bitcoin cryptosystem, the latter is pointless theft, violation of property rights, and arbitrary destruction of property. The former is impressive, the latter is embarrassing.
As long as the effort is asymmetric, we should be fine. In other words, if our total_effort(Change-PoW) < their total_effort(Seize-PoW), then adversaries should not find it in their interest to Seize-PoW.
Conclusion
My conclusion is this: miners canât harm Bitcoin. If an attacker gets 60% or even 99% of the network hashrate, he can do very little. In a world of fungibility and payment channels, he can not censor or otherwise interfere with any payments. If he desires to re-write the chain, he is torn between a âsmall rewriteâ of a few blocks (which is relatively unproductive) and a âlarge rewriteâ of many blocks (which is slow, noticeable, and perilous).
Iâm gravely concerned, that some members of the Bitcoin Community take Satoshiâs qualifier âas long as a majority of CPU power is controlled by nodes that are not cooperating to attack the networkâ to be some kind of Divine Edict. As if, should we fail to obey this rule, we will be expelled from Paradise. In my view, the qualifier was instead a trivial statement of fact: as long as we have X, we will have result Y. The statement âX implies Yâ fully allows us to achieve Y in any number of non-X ways, however much we might prefer to always get our Y from X, whenever possible.
Ultimately, no one can control 100% of the hashpower, or any % of âthe hashpowerâ. This is because the power is itself generated by the value of the coins which are created to bid for it. If we change (with the userâs consent) the PoW algorithm (to something that we will select -at random- tomorrow), then what will âthe hashrateâ be? Where will it be? Who would control it?
By the laws of mathematics, 51% of the hashrate has been owned by one person, or one group of people (who could all conspire with each other), for each and every day of Bitcoins ~3000 day existence.
Bitcoin is not invulnerable. If someone can cheaply and easily obtain 51% of the network hashrate, over and over again, then it cannot survive.
But, make no mistake: that is the threat we need to worry about. Not how many pools control X% hashrate, or how easy it is to fit mining administrators on a stage, or if they all share a mempool or if they all know each otherâs phone number.
Those things donât really matter.
Add Disqus comments.
comments powered by
Disqus
What does cryptoanarchy mean
By Oleg Andreev
Posted January 29, 2017
The word âanarchyâ simply means rejection of a notion that any human being (or group thereof) can be a kind and wise despot to rule all other human beings. However, many people think âanarchyâ means absense of order, lack of ethics and complete apocalypse.
âCryptoanarchyâ means a practical path to protecting human beings against wanna be despots (that is, protecting humans against each other).
Why is it âcryptoâ? Lets be more specific about what we want to achieve:
- Organizations that do what you like should be protected against censorship and shutdown. If you and others want to participate in them, you should have cheap and safe means to do so in a hostile environment.
- Organizations that do what you donât like should not be able to extract support from you. They should rely on voluntary support from their participants and waste as many resources as possible to gain involuntary support.
In other words, we need asymmetric security for society: cooperation should be cheap, intervention should be expensive.
âCryptoâ comes in play because most cryptographic primitives and protocols are built around the idea of asymmetric security: cheap to use, expensive to break.
Turns out, personal communications, money and financial markets are all digital and can be secured via cryptography. Identities can be obfuscated to protect against physical attacks. Money can be decentralized and therefore censorship-resistant, and also cheap to secure. Entire financial markets can be distributed and adaptive to support complex economical relationships even when some parts of the economy are under political pressure.
Implementing these two points does not automatically guarantee happiness to everyone. But it certainly improves individual liberty and gives room for many people to figure out how they want to live without being locked into a vision of a narrow group of psychopaths.